CVE-2026-68584
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChi
CVSS
8.6
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 3 ago 2026 · Última mod.: 3 ago 2026 · CWE-288
Sin historial EPSS suficiente todavía.
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.