GHSA-7v6h-j59w-8qfpMediumCVSS 5.8

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the...

Published
August 13, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.

🔗 References (4)