Summary
CVE-2026-72801 is an information disclosure vulnerability in SiYuan Note, a personal knowledge management application, affecting all versions before v3.7.4. Two unauthenticated API endpoints exposed in "publish mode" leak encrypted-notebook key-derivation material and wrapped data encryption keys, letting an attacker perform unlimited offline password-cracking attempts against a notebook’s master password. The vulnerability is rated HIGH severity (CVSS 8.7).
Technical details
- Root cause:
POST /api/system/getConfreturns theNotebookCryptoconfiguration object, including the Argon2id salt, KDF cost parameters, and a password verifier. The server-sideHideConfSecret()redaction routine, which strips other sensitive configuration fields, does not reference or redactNotebookCrypto. - A second endpoint,
POST /api/notebook/getNotebookConf, returns the wrapped per-notebook data encryption key (WrappedDEK) with no reader-level (publish role) access filtering. - Trigger conditions: the target instance must be running in publish mode with at least one encrypted notebook; no authentication or special privileges are required to reach either endpoint.
- Attack vector: network — an unauthenticated remote attacker sends requests to the two endpoints and harvests the returned cryptographic material.
- Impact: the leaked salt, KDF parameters, verifier, and wrapped keys allow GPU-accelerated, rate-limit-free offline brute-forcing of the notebook master password, ultimately exposing the confidentiality of encrypted notebook contents. Integrity and availability are not affected.
Affected software
- SiYuan (siyuan-note/siyuan), golang package
github.com/siyuan-note/siyuan/kernel - All versions prior to v3.7.4 running in publish mode
Severity
- CVSS v4.0: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: upgrade SiYuan to v3.7.4 or later, which removes
NotebookCryptofrom the unauthenticatedgetConfresponse and applies reader-level filtering togetNotebookConf. - If patching is not immediately possible: disable publish mode for workspaces containing encrypted notebooks, or restrict network access to the publish endpoints to trusted/authenticated sources only.
- After upgrading, consider rotating master passwords for any notebooks that were exposed in publish mode prior to the fix, since previously disclosed key-derivation material could still be brute-forced offline.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Access Authorization - SiYuan,思源笔记 - Raw response body:
exitSiYuan,b3log.org/siyuan

