CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API
CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API Vulnerability ID: CVE-2026-74904 CVSS Score: 8.7 Published: 2026-10-02 A high-severity missing authorization vulnerability (CWE-862) exists
CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API
Vulnerability ID: CVE-2026-74904
CVSS Score: 8.7
Published: 2026-10-02
A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.
TL;DR
Unauthenticated or anonymous users can exploit missing authorization checks in SiYuan's block APIs to retrieve private note contents and map document metadata.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862
- Attack Vector: Network
- CVSS v4.0 Score: 8.7 (High)
- CVSS v3.1 Score: 7.5 (High)
- EPSS Score: 0.00504 (Percentile: 40.87%)
- Impact: Information Disclosure
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- SiYuan Note-Taking Application
-
siyuan: < 3.7.4 (Fixed in:
3.7.4)
Code Analysis
Commit: bd067a4
🔒 Enforce publish access for block metadata and existence endpoints
Exploit Details
- GitHub Security Advisory: Exploit overview and missing authorization mechanics.
Mitigation Strategies
- Upgrade SiYuan to version v3.7.4 or later
- Disable Publish Mode entirely if upgrades cannot be performed
- Restrict network access to port 6806 using firewall rules or a reverse proxy
Remediation Steps:
- Verify the running version of SiYuan using the settings or API interface
- Download the latest version (v3.7.4 or later) from the official GitHub repository or update the container image
- Apply network access controls to ensure the backend port is not exposed directly to the public internet
- Configure a reverse proxy with path-based access controls to block unauthenticated requests to /api/block/*
References
- GitHub Security Advisory GHSA-4vpg-gwqq-w44c
- Fix Commit bd067a4fe9b208c0858d8d9dc6220dc8affc403e
- SiYuan Release v3.8.0
- VulnCheck Advisory for SiYuan Note
- NVD CVE-2026-74904 Detail
Read the full report for CVE-2026-74904 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.