HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-72795 — SiYuan versions before v3.7.4 fail to filter embedded block content by publish a...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.

Analysis

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization. CVSS Score: 8.6. Published: 2026-08-12T20:17:51.137.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72795
Source Attribution

Originally published by NIST NVD on Aug 12, 2026. Verified by: NIST.

Related Threats