SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type. | |
| Title | SiYuan before v3.7.4 Information Disclosure via renderAttributeView | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T19:34:45.544Z
Reserved: 2026-08-10T15:11:03.190Z
Link: CVE-2026-72798
No data.
Status : Received
Published: 2026-08-12T20:17:51.543
Modified: 2026-08-12T20:17:51.543
Link: CVE-2026-72798
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:15:07Z