CVE-2026-72799: SiYuan: broken access control exposes private docs
GHSA-5w7r-f4cg-rqq7 MEDIUM PoC AVAILABLESiYuan, a self-hosted knowledge management tool, ships five filetree endpoints that fail to enforce publish-access checks when an instance runs in publish mode with authentication disabled, letting any unauthenticated visitor or holder of a public reader token enumerate the entire private document tree — notebook names, folder structure, document titles, and even the IDs of documents explicitly marked hidden, password-protected, or publish-forbidden. There's no code execution or data tampering here (CVSS 5.8, confidentiality-only impact), but the attack requires zero privileges and zero complexity, and CISA's SSVC decision is TRACK rather than Attend, consistent with the low EPSS score (0.237%) and absence of a public exploit or Nuclei template. The real risk is reconnaissance value: an adversary who maps a target's private knowledge structure gains a roadmap for social engineering, targeted document requests, or chaining into other vulnerabilities using the leaked document IDs. Any organization running SiYuan in publish mode facing the internet should upgrade to v3.7.4 immediately, and until patched, set Publish.Auth.Enable to true or place the instance behind an authenticating reverse proxy. Detection teams should watch access logs for unauthenticated calls to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath from unrecognized clients.
What is the risk?
Medium severity (CVSS 5.8) driven by a broken-access-control flaw (CWE-862) that is trivial to exploit — network-reachable, no authentication, no user interaction, low attack complexity. Impact is confined to confidentiality (C:L) with no integrity or availability loss, so this is an information-disclosure/reconnaissance issue rather than a compromise primitive. Exploitation likelihood is low in absolute terms (EPSS 0.00237) and there's no evidence of active exploitation (not in CISA KEV, SSVC = TRACK, no public exploit or scanner template known), but the zero-cost nature of the attack means any internet-facing instance running publish mode without Publish.Auth.Enable is exposed to opportunistic scanning the moment it's discovered.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260724112156-5bae0926b896 | 0.0.0-20260724112156-5bae0926b896 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
1) Upgrade SiYuan to v3.7.4 or later, which enforces the publish-access filter on all five affected endpoints. 2) Interim workaround: set Publish.Auth.Enable to true so publish mode requires a reader token, removing the fully anonymous exposure. 3) For instances that must stay on an older version, restrict publish-mode network exposure to trusted networks or place it behind a reverse proxy that requires authentication before requests reach SiYuan. 4) Detection: review access/reverse-proxy logs for repeated unauthenticated requests to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath, which would indicate tree-enumeration activity.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72799?
SiYuan, a self-hosted knowledge management tool, ships five filetree endpoints that fail to enforce publish-access checks when an instance runs in publish mode with authentication disabled, letting any unauthenticated visitor or holder of a public reader token enumerate the entire private document tree — notebook names, folder structure, document titles, and even the IDs of documents explicitly marked hidden, password-protected, or publish-forbidden. There's no code execution or data tampering here (CVSS 5.8, confidentiality-only impact), but the attack requires zero privileges and zero complexity, and CISA's SSVC decision is TRACK rather than Attend, consistent with the low EPSS score (0.237%) and absence of a public exploit or Nuclei template. The real risk is reconnaissance value: an adversary who maps a target's private knowledge structure gains a roadmap for social engineering, targeted document requests, or chaining into other vulnerabilities using the leaked document IDs. Any organization running SiYuan in publish mode facing the internet should upgrade to v3.7.4 immediately, and until patched, set Publish.Auth.Enable to true or place the instance behind an authenticating reverse proxy. Detection teams should watch access logs for unauthenticated calls to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath from unrecognized clients.
Is CVE-2026-72799 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72799, increasing the risk of exploitation.
How to fix CVE-2026-72799?
1) Upgrade SiYuan to v3.7.4 or later, which enforces the publish-access filter on all five affected endpoints. 2) Interim workaround: set Publish.Auth.Enable to true so publish mode requires a reader token, removing the fully anonymous exposure. 3) For instances that must stay on an older version, restrict publish-mode network exposure to trusted networks or place it behind a reverse proxy that requires authentication before requests reach SiYuan. 4) Detection: review access/reverse-proxy logs for repeated unauthenticated requests to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath, which would indicate tree-enumeration activity.
What systems are affected by CVE-2026-72799?
This vulnerability affects the following AI/ML architecture patterns: knowledge management / PKM platforms, self-hosted publish-mode web applications, RAG pipelines (when SiYuan content is indexed as a retrieval source).
What is the CVSS score for CVE-2026-72799?
CVE-2026-72799 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0007 Discover AI Artifacts AML.T0036 Data from Information Repositories AML.T0064 Gather RAG-Indexed Targets Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapping notebook names, folder hierarchies, and document titles, and resolving title paths to document IDs, including for documents marked hidden, password-protected, or publish-forbidden.
Exploitation Scenario
An attacker finds a SiYuan instance exposed in publish mode (e.g., via search-engine discovery or scanning) where the operator never enabled Publish.Auth.Enable. Without any credentials, the attacker calls getFullHPathByID and getIDsByHPath in a loop, walking the notebook and folder hierarchy and collecting the titles and IDs of every document — including ones the owner explicitly hid, password-protected, or marked as forbidden from publishing. The attacker now has a complete map of the target's private knowledge base structure and a set of internal document IDs, which they use to identify high-value targets (e.g., a document titled 'API keys' or 'incident response plan') for further probing, phishing pretext, or chaining with any future vulnerability that accepts a document ID.
Weaknesses (CWE)
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-5w7r-f4cg-rqq7
- vulncheck.com/advisories/siyuan-before-information-disclosure-via-path-resolution
- github.com/advisories/GHSA-5w7r-f4cg-rqq7
- github.com/siyuan-note/siyuan/commit/5bae0926b896eaff0bc5cc6a75d421c2d161a806
- nvd.nist.gov/vuln/detail/CVE-2026-72799
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook