SiYuan before v3.7.4 Information Disclosure via resolveAssetPath
Published Aug 12, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.33%
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout.
Affected products
-
Affected
- ≥ 0, < 3.7.4
Unaffected
- 3.7.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Siyuan-Note | Siyuan | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/siyuan-note/siyuan/kernel
Go
Introduced 0 Fixed 0.0.0-20260724095509-eee3410aa131
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/siyuan-note/siyuan/kernel | 0 | 0.0.0-20260724095509-eee3410aa131 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57462 Advisory
- https://github.com/advisories/GHSA-jv8v-xq2h-657v Advisory
- https://github.com/siyuan-note/siyuan/commit/eee3410aa131b76f1bd72e933d484cf1ece77e88
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jv8v-xq2h-657v exploitvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-72802
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-resolveassetpath third-party-advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub