Threat Advisory

SiYuan Notebook Flaw Exposes Hidden Notebooks and Data

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version(s) not explicitly stated. These vulnerabilities pose a moderate to high risk of unauthorized access and data exposure.

CVE-2026-72790 (CVSS 7.5 — High): A vulnerability was discovered where notebook name, document count, size, and timestamps are returned for any notebook, including those hidden from readers,.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version(s) not explicitly stated. These vulnerabilities pose a moderate to high risk of unauthorized access and data exposure.

CVE-2026-72790 (CVSS 7.5 — High): A vulnerability was discovered where notebook name, document count, size, and timestamps are returned for any notebook, including those hidden from readers,.[emaillocker id="1283"]

CVE-2026-72789: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked.

These vulnerabilities collectively present a risk of unauthorized access and data exposure.

RECOMMENDATION:

We recommend you to update SiYuan to version 0.0.0-20260726005141-9edb321eb451.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu