Summary
CVE-2026-74906 is an incorrect authorization (CWE-863) vulnerability affecting SiYuan Note, a self-hosted personal knowledge management and note-taking application, in all versions prior to 3.7.4. Eight reader-facing endpoints in SiYuan’s Publish service filter content using a document visibility list instead of the intended disable (access-control) list, allowing unauthenticated remote visitors to discover and read the contents of documents that workspace owners explicitly marked as forbidden from publishing. The flaw carries a CVSS v4.0 base score of 8.7 (High), reflecting a network-exploitable, no-authentication confidentiality breach.
Technical details
- Root cause: SiYuan’s publish-access model maintains two independent controls per document (
PublishAccessItem):Visible(controls whether a document appears in navigation) andDisable(controls whether the document’s content can actually be accessed). The eight affected endpoints incorrectly callGetInvisiblePublishAccess()to filter results instead ofGetDisablePublishAccess(), so documents withDisable=truebutVisible=trueremain reachable through these endpoints. - Trigger conditions: A SiYuan workspace must have its Publish service enabled (i.e., publicly exposed publish/kernel endpoints), with at least one document flagged as disabled/forbidden from publishing while still marked visible in navigation.
- Attack vector: Network-based, unauthenticated. No user interaction or privileges are required — an anonymous visitor can send requests directly to the affected API endpoints.
- Impact: Confidentiality breach only (no integrity or availability impact). Attackers can read content the workspace owner intended to keep private, via full-text search results, backlinks, asset content, saved search criteria, recent documents lists, the document graph, and tag listings.
- Affected endpoints:
POST /api/filetree/searchDocsPOST /api/ref/getBacklinkandgetBacklink2POST /api/search/getAssetContent,getAssetContentByPath,fullTextSearchAssetContentPOST /api/storage/getCriteriaPOST /api/storage/getRecentDocsPOST /api/graph/getGraphandgetLocalGraphPOST /api/tag/getTag
Affected software
- Product: SiYuan (siyuan-note / B3log), Go module
github.com/siyuan-note/siyuan/kernel - Affected versions: All versions prior to 3.7.4 (confirmed vulnerable: v3.7.3)
- Fixed version: 3.7.4 and later
Severity
- CVSS v4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CWE: CWE-863 (Incorrect Authorization)
Mitigation and recommended actions
- Immediate: Upgrade SiYuan to version 3.7.4 or later, which fixes the affected endpoints to correctly filter using the disable/access-control list rather than the visibility list.
- If immediate patching is not possible:
- Restrict or disable public exposure of the SiYuan Publish service until patched.
- Audit documents currently marked as "forbidden from publishing" (
Disable) and verify no sensitive content was exposed via the affected search, backlink, asset, criteria, recent-documents, graph, or tag endpoints while the instance was internet-exposed. - Place the publish/kernel endpoints behind network-level access controls (e.g., allow-listing, VPN, or reverse-proxy authentication) as a compensating control until the upgrade is applied.

