Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API Vulnerability ID: CVE-2026-74904 CVSS Score: 8.7 Published: 2026-10-02 A high-severity missing authorization vulnerability (CWE-862) exists

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

Vulnerability ID: CVE-2026-74904
CVSS Score: 8.7
Published: 2026-10-02

A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.

TL;DR

Unauthenticated or anonymous users can exploit missing authorization checks in SiYuan's block APIs to retrieve private note contents and map document metadata.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862
  • Attack Vector: Network
  • CVSS v4.0 Score: 8.7 (High)
  • CVSS v3.1 Score: 7.5 (High)
  • EPSS Score: 0.00504 (Percentile: 40.87%)
  • Impact: Information Disclosure
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • SiYuan Note-Taking Application
  • siyuan: < 3.7.4 (Fixed in: 3.7.4)

Code Analysis

Commit: bd067a4

🔒 Enforce publish access for block metadata and existence endpoints

Exploit Details

Mitigation Strategies

  • Upgrade SiYuan to version v3.7.4 or later
  • Disable Publish Mode entirely if upgrades cannot be performed
  • Restrict network access to port 6806 using firewall rules or a reverse proxy

Remediation Steps:

  1. Verify the running version of SiYuan using the settings or API interface
  2. Download the latest version (v3.7.4 or later) from the official GitHub repository or update the container image
  3. Apply network access controls to ensure the backend port is not exposed directly to the public internet
  4. Configure a reverse proxy with path-based access controls to block unauthenticated requests to /api/block/*

References

Read the full report for CVE-2026-74904 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.