CVE-2026-72799: SiYuan: broken access control exposes private docs

GHSA-5w7r-f4cg-rqq7 MEDIUM PoC AVAILABLE
Published August 12, 2026
CISO Take

SiYuan, a self-hosted knowledge management tool, ships five filetree endpoints that fail to enforce publish-access checks when an instance runs in publish mode with authentication disabled, letting any unauthenticated visitor or holder of a public reader token enumerate the entire private document tree — notebook names, folder structure, document titles, and even the IDs of documents explicitly marked hidden, password-protected, or publish-forbidden. There's no code execution or data tampering here (CVSS 5.8, confidentiality-only impact), but the attack requires zero privileges and zero complexity, and CISA's SSVC decision is TRACK rather than Attend, consistent with the low EPSS score (0.237%) and absence of a public exploit or Nuclei template. The real risk is reconnaissance value: an adversary who maps a target's private knowledge structure gains a roadmap for social engineering, targeted document requests, or chaining into other vulnerabilities using the leaked document IDs. Any organization running SiYuan in publish mode facing the internet should upgrade to v3.7.4 immediately, and until patched, set Publish.Auth.Enable to true or place the instance behind an authenticating reverse proxy. Detection teams should watch access logs for unauthenticated calls to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath from unrecognized clients.

Sources: NVD GitHub Advisory EPSS ATLAS vulncheck.com

What is the risk?

Medium severity (CVSS 5.8) driven by a broken-access-control flaw (CWE-862) that is trivial to exploit — network-reachable, no authentication, no user interaction, low attack complexity. Impact is confined to confidentiality (C:L) with no integrity or availability loss, so this is an information-disclosure/reconnaissance issue rather than a compromise primitive. Exploitation likelihood is low in absolute terms (EPSS 0.00237) and there's no evidence of active exploitation (not in CISA KEV, SSVC = TRACK, no public exploit or scanner template known), but the zero-cost nature of the attack means any internet-facing instance running publish mode without Publish.Auth.Enable is exposed to opportunistic scanning the moment it's discovered.

How does the attack unfold?

Discovery
Attacker identifies a network-reachable SiYuan instance running in publish mode with Publish.Auth.Enable disabled.
AML.T0006
Unauthenticated enumeration
Attacker calls the five filetree endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, getHPathByPath) without credentials to walk the notebook and folder hierarchy.
AML.T0036
Sensitive document identification
Enumeration reveals titles and IDs of hidden, password-protected, and publish-forbidden documents alongside publicly intended ones.
AML.T0007
Follow-on targeting
Attacker uses the leaked document map and IDs to prioritize social engineering, targeted requests, or chaining with other vulnerabilities against high-value private documents.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260724112156-5bae0926b896 0.0.0-20260724112156-5bae0926b896
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.3%
chance of exploitation in 30 days
Higher than 23% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C Low
I None
A None

What should I do?

1 step
  1. 1) Upgrade SiYuan to v3.7.4 or later, which enforces the publish-access filter on all five affected endpoints. 2) Interim workaround: set Publish.Auth.Enable to true so publish mode requires a reader token, removing the fully anonymous exposure. 3) For instances that must stay on an older version, restrict publish-mode network exposure to trusted networks or place it behind a reverse proxy that requires authentication before requests reach SiYuan. 4) Detection: review access/reverse-proxy logs for repeated unauthenticated requests to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath, which would indicate tree-enumeration activity.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.7.2 - Data for AI systems
NIST AI RMF
MEASURE 2.7 - AI system security and resilience are evaluated
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72799?

SiYuan, a self-hosted knowledge management tool, ships five filetree endpoints that fail to enforce publish-access checks when an instance runs in publish mode with authentication disabled, letting any unauthenticated visitor or holder of a public reader token enumerate the entire private document tree — notebook names, folder structure, document titles, and even the IDs of documents explicitly marked hidden, password-protected, or publish-forbidden. There's no code execution or data tampering here (CVSS 5.8, confidentiality-only impact), but the attack requires zero privileges and zero complexity, and CISA's SSVC decision is TRACK rather than Attend, consistent with the low EPSS score (0.237%) and absence of a public exploit or Nuclei template. The real risk is reconnaissance value: an adversary who maps a target's private knowledge structure gains a roadmap for social engineering, targeted document requests, or chaining into other vulnerabilities using the leaked document IDs. Any organization running SiYuan in publish mode facing the internet should upgrade to v3.7.4 immediately, and until patched, set Publish.Auth.Enable to true or place the instance behind an authenticating reverse proxy. Detection teams should watch access logs for unauthenticated calls to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath from unrecognized clients.

Is CVE-2026-72799 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72799, increasing the risk of exploitation.

How to fix CVE-2026-72799?

1) Upgrade SiYuan to v3.7.4 or later, which enforces the publish-access filter on all five affected endpoints. 2) Interim workaround: set Publish.Auth.Enable to true so publish mode requires a reader token, removing the fully anonymous exposure. 3) For instances that must stay on an older version, restrict publish-mode network exposure to trusted networks or place it behind a reverse proxy that requires authentication before requests reach SiYuan. 4) Detection: review access/reverse-proxy logs for repeated unauthenticated requests to getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, or getHPathByPath, which would indicate tree-enumeration activity.

What systems are affected by CVE-2026-72799?

This vulnerability affects the following AI/ML architecture patterns: knowledge management / PKM platforms, self-hosted publish-mode web applications, RAG pipelines (when SiYuan content is indexed as a retrieval source).

What is the CVSS score for CVE-2026-72799?

CVE-2026-72799 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.

What is the AI security impact?

Affected AI Architectures

knowledge management / PKM platformsself-hosted publish-mode web applicationsRAG pipelines (when SiYuan content is indexed as a retrieval source)

MITRE ATLAS Techniques

AML.T0007 Discover AI Artifacts
AML.T0036 Data from Information Repositories
AML.T0064 Gather RAG-Indexed Targets

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.7.2
NIST AI RMF: MEASURE 2.7
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapping notebook names, folder hierarchies, and document titles, and resolving title paths to document IDs, including for documents marked hidden, password-protected, or publish-forbidden.

Exploitation Scenario

An attacker finds a SiYuan instance exposed in publish mode (e.g., via search-engine discovery or scanning) where the operator never enabled Publish.Auth.Enable. Without any credentials, the attacker calls getFullHPathByID and getIDsByHPath in a loop, walking the notebook and folder hierarchy and collecting the titles and IDs of every document — including ones the owner explicitly hid, password-protected, or marked as forbidden from publishing. The attacker now has a complete map of the target's private knowledge base structure and a set of internal document IDs, which they use to identify high-value targets (e.g., a document titled 'API keys' or 'incident response plan') for further probing, phishing pretext, or chaining with any future vulnerability that accepts a document ID.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 4, 2026
First Seen
August 12, 2026

Related Vulnerabilities