VULNERABILITY INTELLIGENCE
CVE-2026-72802
CVSS score6.9 MEDIUM
EPSS probability0.33%
CISA KEVNot currently listed
Published2026-08-12
Last modified2026-08-26
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout.
Weakness classification
- CWE-639: Authorization Bypass Through User-Controlled Key