CVE-2026-72797: SiYuan: missing authz leaks encrypted notebook metadata
GHSA-f2rw-w22v-54vh MEDIUM PoC AVAILABLESiYuan before v3.7.4 exposes an unauthenticated endpoint, getEncryptedNotebookStatus, that returns the identifiers, names, and lock/unlock state of encrypted notebooks to anonymous readers and publish-mode accounts, without checking whether the requester actually has publish access. This matters less for raw severity — CVSS 5.8 medium, confidentiality-only impact, EPSS still low, no CISA KEV listing, no public exploit or Nuclei template — and more because it is a zero-effort reconnaissance primitive: no credentials, no user interaction, and it hands an attacker a map of which encrypted notebooks exist, what they're named, and whether they're currently unlocked in memory. For self-hosted SiYuan instances used as personal or team knowledge bases (including AI-assisted note-taking), that metadata is enough to target social engineering or time follow-on attacks against a notebook while it sits unlocked. Upgrade to v3.7.4 or later; until patched, restrict or disable public/publish-mode access to SiYuan instances and audit access logs for repeated calls to the endpoint as an enumeration signal.
What is the risk?
Medium risk overall: the flaw requires no authentication or user interaction and is trivially scriptable (AV:N/AC:L/PR:N/UI:N), but the CVSS vector caps impact at confidentiality-low with no integrity or availability effect (C:L/I:N/A:N) — only metadata (IDs, names, lock state) is exposed, not notebook contents. EPSS remains low and the CVE is not in CISA KEV, has no public exploit code, and no Nuclei template exists, so mass exploitation is unlikely in the near term. The realistic risk is targeted: an attacker who already has some form of access to a publish-mode SiYuan deployment (a common self-hosted note-taking setup) can use this to fingerprint sensitive notebooks and time follow-on attacks.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260724123622-8fb1b5766093 | 0.0.0-20260724123622-8fb1b5766093 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade SiYuan to v3.7.4 or later, which adds publish-access filtering to getEncryptedNotebookStatus. Until patched: do not expose publish-mode SiYuan instances directly to the internet without a reverse-proxy access control layer (VPN, IP allowlist, or auth gate in front of publish endpoints); disable publish mode for encrypted notebooks if not strictly needed. Detection: monitor web server / reverse proxy logs for repeated unauthenticated calls to getEncryptedNotebookStatus as an enumeration indicator, and review who has publish-mode account access. Reference the vendor advisory (GHSA-f2rw-w22v-54vh) and VulnCheck write-up for patch details.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72797?
SiYuan before v3.7.4 exposes an unauthenticated endpoint, getEncryptedNotebookStatus, that returns the identifiers, names, and lock/unlock state of encrypted notebooks to anonymous readers and publish-mode accounts, without checking whether the requester actually has publish access. This matters less for raw severity — CVSS 5.8 medium, confidentiality-only impact, EPSS still low, no CISA KEV listing, no public exploit or Nuclei template — and more because it is a zero-effort reconnaissance primitive: no credentials, no user interaction, and it hands an attacker a map of which encrypted notebooks exist, what they're named, and whether they're currently unlocked in memory. For self-hosted SiYuan instances used as personal or team knowledge bases (including AI-assisted note-taking), that metadata is enough to target social engineering or time follow-on attacks against a notebook while it sits unlocked. Upgrade to v3.7.4 or later; until patched, restrict or disable public/publish-mode access to SiYuan instances and audit access logs for repeated calls to the endpoint as an enumeration signal.
Is CVE-2026-72797 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72797, increasing the risk of exploitation.
How to fix CVE-2026-72797?
Upgrade SiYuan to v3.7.4 or later, which adds publish-access filtering to getEncryptedNotebookStatus. Until patched: do not expose publish-mode SiYuan instances directly to the internet without a reverse-proxy access control layer (VPN, IP allowlist, or auth gate in front of publish endpoints); disable publish mode for encrypted notebooks if not strictly needed. Detection: monitor web server / reverse proxy logs for repeated unauthenticated calls to getEncryptedNotebookStatus as an enumeration indicator, and review who has publish-mode account access. Reference the vendor advisory (GHSA-f2rw-w22v-54vh) and VulnCheck write-up for patch details.
What systems are affected by CVE-2026-72797?
This vulnerability affects the following AI/ML architecture patterns: RAG pipelines, self-hosted knowledge bases.
What is the CVSS score for CVE-2026-72797?
CVE-2026-72797 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0036 Data from Information Repositories AML.T0064 Gather RAG-Indexed Targets Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.
Exploitation Scenario
An attacker locates a publicly reachable SiYuan instance running in publish mode (common for self-hosted note-sharing setups) and, without authenticating, calls getEncryptedNotebookStatus. The response enumerates every encrypted notebook's ID, name, and current lock state. The attacker now knows a notebook named "Client Credentials" exists and is periodically unlocked during business hours. They use the notebook name to craft a convincing phishing email to the notebook owner referencing it by name, or they poll the endpoint to catch the window when the notebook is unlocked in memory and pivot to other endpoints or client-side attacks to attempt to read its contents during that window.
Weaknesses (CWE)
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-f2rw-w22v-54vh
- vulncheck.com/advisories/siyuan-before-information-disclosure-via-getencryptednotebookstatus
- github.com/advisories/GHSA-f2rw-w22v-54vh
- github.com/siyuan-note/siyuan/commit/8fb1b5766093371f6a516c221c92026b904fe779
- nvd.nist.gov/vuln/detail/CVE-2026-72797
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook