CVE-2026-72808: SiYuan: authZ gap leaks private PDF annotations
GHSA-v7ph-r5r6-4jcj MEDIUM PoC AVAILABLE CISA: TRACK*SiYuan's /api/asset/getFileAnnotation endpoint checks only that a caller is authenticated (CheckAuth), not that they're allowed to view the specific document, so anyone who knows an asset path — an anonymous reader when publish authentication is disabled, or any low-privilege publish RoleReader — can pull the private PDF highlights and notes attached to password-protected or unpublished documents. This matters for CISOs running SiYuan as an internal knowledge base or AI-assisted note tool: exploitation needs no privileges and no user interaction (CVSS 3.1 5.8, AV:N/AC:L/PR:N/UI:N), but EPSS sits at just 0.28% and CISA's SSVC call is TRACK_STAR rather than an active-exploitation signal, and there's no public PoC or Nuclei template yet, so mass scanning is unlikely near-term. Blast radius is confidentiality-only — no integrity or availability impact, and encrypted notebooks are unaffected. Patch to SiYuan v3.7.4, where the endpoint's access check is aligned with the /assets/* route; until then, disable anonymous publish access, tighten issuance of publish RoleReader accounts, and watch access logs for repeated getFileAnnotation calls against asset paths outside a user's normal read pattern.
What is the risk?
Medium risk. The flaw is trivially exploitable (no auth required when publish auth is off, no privilege escalation needed, no user interaction) but the impact is narrow: confidentiality-only disclosure of PDF annotation metadata (highlights/notes), not the underlying document, source code, or credentials. No integrity or availability impact, no CISA KEV listing, no public exploit or scanner template, and EPSS remains near-zero (0.283%). Real-world risk is concentrated in organizations that run SiYuan's publish feature with anonymous access enabled or that issue broad RoleReader access to non-encrypted notebooks containing sensitive commentary.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260723031702-509b35055940 | 0.0.0-20260723031702-509b35055940 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to SiYuan v3.7.4 or later, where getFileAnnotation enforces the same publish-access/password check as /assets/*. Until patched: disable anonymous publish access (require publish authentication), minimize and audit publish RoleReader account issuance, and move genuinely sensitive notebooks into encrypted boxes since encrypted-box annotations are not exposed by this bug. Monitor access/reverse-proxy logs for repeated or scripted calls to /api/asset/getFileAnnotation against asset paths a given reader shouldn't know, which would indicate enumeration attempts.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72808?
SiYuan's /api/asset/getFileAnnotation endpoint checks only that a caller is authenticated (CheckAuth), not that they're allowed to view the specific document, so anyone who knows an asset path — an anonymous reader when publish authentication is disabled, or any low-privilege publish RoleReader — can pull the private PDF highlights and notes attached to password-protected or unpublished documents. This matters for CISOs running SiYuan as an internal knowledge base or AI-assisted note tool: exploitation needs no privileges and no user interaction (CVSS 3.1 5.8, AV:N/AC:L/PR:N/UI:N), but EPSS sits at just 0.28% and CISA's SSVC call is TRACK_STAR rather than an active-exploitation signal, and there's no public PoC or Nuclei template yet, so mass scanning is unlikely near-term. Blast radius is confidentiality-only — no integrity or availability impact, and encrypted notebooks are unaffected. Patch to SiYuan v3.7.4, where the endpoint's access check is aligned with the /assets/* route; until then, disable anonymous publish access, tighten issuance of publish RoleReader accounts, and watch access logs for repeated getFileAnnotation calls against asset paths outside a user's normal read pattern.
Is CVE-2026-72808 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72808, increasing the risk of exploitation.
How to fix CVE-2026-72808?
Upgrade to SiYuan v3.7.4 or later, where getFileAnnotation enforces the same publish-access/password check as /assets/*. Until patched: disable anonymous publish access (require publish authentication), minimize and audit publish RoleReader account issuance, and move genuinely sensitive notebooks into encrypted boxes since encrypted-box annotations are not exposed by this bug. Monitor access/reverse-proxy logs for repeated or scripted calls to /api/asset/getFileAnnotation against asset paths a given reader shouldn't know, which would indicate enumeration attempts.
What systems are affected by CVE-2026-72808?
This vulnerability affects the following AI/ML architecture patterns: knowledge management platforms, AI-assisted note-taking tools.
What is the CVSS score for CVE-2026-72808?
CVE-2026-72808 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.40%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0036 Data from Information Repositories Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by CheckAuth (unlike the /assets/* route, which enforces publish access and password), an anonymous reader (when publish authentication is disabled) or any publish RoleReader who knows an asset path can read the private PDF annotations (highlights and notes) of publish-forbidden, password-protected, or unpublished documents. The issue is limited to non-encrypted notebooks; encrypted-box annotations are not exposed.
Exploitation Scenario
An attacker locates a SiYuan publish instance (via search engine indexing or a shared link) and either operates anonymously if publish authentication is disabled, or registers/obtains a low-privilege RoleReader account if it's enabled. They identify or guess the asset path of a PDF that the publish settings mark as forbidden, password-protected, or unpublished, then call /api/asset/getFileAnnotation directly with that path. Because this endpoint only checks CheckAuth and skips the publish-access/password gate applied to the normal /assets/* route, it returns the raw .sya annotation content — highlights and margin notes — letting the attacker read private commentary on a document without ever passing the protection meant to gate the PDF itself.
Weaknesses (CWE)
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-v7ph-r5r6-4jcj
- vulncheck.com/advisories/siyuan-before-information-disclosure-via-getfileannotation
- github.com/advisories/GHSA-v7ph-r5r6-4jcj
- github.com/siyuan-note/siyuan/commit/509b35055940856ec1c89cb4888723c4660b776a
- nvd.nist.gov/vuln/detail/CVE-2026-72808
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook