Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers. | |
| Title | SiYuan before v3.7.4 Information Disclosure via getNotebookInfo | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T19:37:57.110Z
Reserved: 2026-08-10T15:10:15.963Z
Link: CVE-2026-72790
Updated: 2026-08-12T19:37:43.658Z
Status : Received
Published: 2026-08-12T20:17:50.407
Modified: 2026-08-12T20:17:50.407
Link: CVE-2026-72790
No data.
OpenCVE Enrichment
No data.