CVE-2026-72808: SiYuan: authZ gap leaks private PDF annotations

GHSA-v7ph-r5r6-4jcj MEDIUM PoC AVAILABLE CISA: TRACK*
Published August 12, 2026
CISO Take

SiYuan's /api/asset/getFileAnnotation endpoint checks only that a caller is authenticated (CheckAuth), not that they're allowed to view the specific document, so anyone who knows an asset path — an anonymous reader when publish authentication is disabled, or any low-privilege publish RoleReader — can pull the private PDF highlights and notes attached to password-protected or unpublished documents. This matters for CISOs running SiYuan as an internal knowledge base or AI-assisted note tool: exploitation needs no privileges and no user interaction (CVSS 3.1 5.8, AV:N/AC:L/PR:N/UI:N), but EPSS sits at just 0.28% and CISA's SSVC call is TRACK_STAR rather than an active-exploitation signal, and there's no public PoC or Nuclei template yet, so mass scanning is unlikely near-term. Blast radius is confidentiality-only — no integrity or availability impact, and encrypted notebooks are unaffected. Patch to SiYuan v3.7.4, where the endpoint's access check is aligned with the /assets/* route; until then, disable anonymous publish access, tighten issuance of publish RoleReader accounts, and watch access logs for repeated getFileAnnotation calls against asset paths outside a user's normal read pattern.

Sources: NVD GitHub Advisory EPSS CISA KEV ATLAS vulncheck.com

What is the risk?

Medium risk. The flaw is trivially exploitable (no auth required when publish auth is off, no privilege escalation needed, no user interaction) but the impact is narrow: confidentiality-only disclosure of PDF annotation metadata (highlights/notes), not the underlying document, source code, or credentials. No integrity or availability impact, no CISA KEV listing, no public exploit or scanner template, and EPSS remains near-zero (0.283%). Real-world risk is concentrated in organizations that run SiYuan's publish feature with anonymous access enabled or that issue broad RoleReader access to non-encrypted notebooks containing sensitive commentary.

How does the attack unfold?

Recon
Attacker locates a SiYuan publish instance and identifies or guesses the asset path of a target PDF, either via search-engine indexing of the publish site or by enumerating publish RoleReader-accessible content.
AML.T0003
Exploitation
Attacker calls /api/asset/getFileAnnotation directly with the asset path; the endpoint checks only CheckAuth and skips the publish-access/password gate enforced by /assets/*, so an anonymous reader or low-privilege RoleReader can invoke it successfully.
AML.T0049
Impact
The raw .sya file content — private PDF highlights and notes — is returned, disclosing confidential commentary on a publish-forbidden, password-protected, or unpublished document without ever passing the intended protection on the underlying PDF.
AML.T0036

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260723031702-509b35055940 0.0.0-20260723031702-509b35055940
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 32% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C Low
I None
A None

What should I do?

1 step
  1. Upgrade to SiYuan v3.7.4 or later, where getFileAnnotation enforces the same publish-access/password check as /assets/*. Until patched: disable anonymous publish access (require publish authentication), minimize and audit publish RoleReader account issuance, and move genuinely sensitive notebooks into encrypted boxes since encrypted-box annotations are not exposed by this bug. Monitor access/reverse-proxy logs for repeated or scripted calls to /api/asset/getFileAnnotation against asset paths a given reader shouldn't know, which would indicate enumeration attempts.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2.2 - Data resources
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72808?

SiYuan's /api/asset/getFileAnnotation endpoint checks only that a caller is authenticated (CheckAuth), not that they're allowed to view the specific document, so anyone who knows an asset path — an anonymous reader when publish authentication is disabled, or any low-privilege publish RoleReader — can pull the private PDF highlights and notes attached to password-protected or unpublished documents. This matters for CISOs running SiYuan as an internal knowledge base or AI-assisted note tool: exploitation needs no privileges and no user interaction (CVSS 3.1 5.8, AV:N/AC:L/PR:N/UI:N), but EPSS sits at just 0.28% and CISA's SSVC call is TRACK_STAR rather than an active-exploitation signal, and there's no public PoC or Nuclei template yet, so mass scanning is unlikely near-term. Blast radius is confidentiality-only — no integrity or availability impact, and encrypted notebooks are unaffected. Patch to SiYuan v3.7.4, where the endpoint's access check is aligned with the /assets/* route; until then, disable anonymous publish access, tighten issuance of publish RoleReader accounts, and watch access logs for repeated getFileAnnotation calls against asset paths outside a user's normal read pattern.

Is CVE-2026-72808 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72808, increasing the risk of exploitation.

How to fix CVE-2026-72808?

Upgrade to SiYuan v3.7.4 or later, where getFileAnnotation enforces the same publish-access/password check as /assets/*. Until patched: disable anonymous publish access (require publish authentication), minimize and audit publish RoleReader account issuance, and move genuinely sensitive notebooks into encrypted boxes since encrypted-box annotations are not exposed by this bug. Monitor access/reverse-proxy logs for repeated or scripted calls to /api/asset/getFileAnnotation against asset paths a given reader shouldn't know, which would indicate enumeration attempts.

What systems are affected by CVE-2026-72808?

This vulnerability affects the following AI/ML architecture patterns: knowledge management platforms, AI-assisted note-taking tools.

What is the CVSS score for CVE-2026-72808?

CVE-2026-72808 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.40%.

What is the AI security impact?

Affected AI Architectures

knowledge management platformsAI-assisted note-taking tools

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0036 Data from Information Repositories

Compliance Controls Affected

ISO 42001: A.6.2.2
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by CheckAuth (unlike the /assets/* route, which enforces publish access and password), an anonymous reader (when publish authentication is disabled) or any publish RoleReader who knows an asset path can read the private PDF annotations (highlights and notes) of publish-forbidden, password-protected, or unpublished documents. The issue is limited to non-encrypted notebooks; encrypted-box annotations are not exposed.

Exploitation Scenario

An attacker locates a SiYuan publish instance (via search engine indexing or a shared link) and either operates anonymously if publish authentication is disabled, or registers/obtains a low-privilege RoleReader account if it's enabled. They identify or guess the asset path of a PDF that the publish settings mark as forbidden, password-protected, or unpublished, then call /api/asset/getFileAnnotation directly with that path. Because this endpoint only checks CheckAuth and skips the publish-access/password gate applied to the normal /assets/* route, it returns the raw .sya annotation content — highlights and margin notes — letting the attacker read private commentary on a document without ever passing the protection meant to gate the PDF itself.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 3, 2026
First Seen
August 12, 2026

Related Vulnerabilities