Summary
CVE-2026-72793 is an information disclosure vulnerability in SiYuan Note, a self-hosted note-taking/knowledge-base application, caused by insufficiently protected credentials (CWE-522) in the /api/system/getConf kernel endpoint. Unauthenticated users and users with only publish-reader access can retrieve secrets that allow forging valid session cookies and, on instances without an access-auth code configured, escalating to administrator access. The issue is rated CRITICAL, with a CVSS v4.0 base score of 9.2.
Technical details
- Root cause:
/api/system/getConfreturns the raw kernel configuration object using a blocklist that enumerates individual fields to strip, rather than reusing the allowlist already used by the/api/system/exportConfendpoint; any field not explicitly added to the blocklist is returned by default. - Exposed fields include
CookieKey(the HMAC key used to sign session cookies),Export.PandocBin(an absolute filesystem path revealing the OS username), andNotebookCrypto(encrypted-notebook key material). - Trigger conditions: a simple request to the
getConfendpoint; no authentication is required, and users with only "publish-reader" privileges can also reach it. - Attack vector: Network, no privileges and no user interaction required (AV:N/PR:N/UI:N).
- Impact: disclosure of the session-cookie signing key enables forging or tampering with authenticated session cookies to impersonate other users; combined with the absence of an access-auth code, this can lead to full administrator takeover. OS username and notebook key material are also exposed.
Affected software
- SiYuan Note (
github.com/siyuan-note/siyuan/kernel), all versions up to and including 3.7.3 - Fixed in version 3.7.4
Severity
- CVSS v4.0: 9.2 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N - CVSS v3.1: 8.6 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade SiYuan Note to version 3.7.4 or later, where the affected fields are no longer returned by the
getConfendpoint. - If immediate patching is not possible: ensure an access-auth code is configured on all internet-exposed SiYuan instances to reduce the impact of exposed credentials, restrict network access to the SiYuan kernel/API port to trusted hosts only, and rotate any session and notebook encryption keys after upgrading.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Access Authorization - SiYuan,思源笔记 - Raw response body:
exitSiYuan,b3log.org/siyuan

