chiprook
← Security
SecurityOctober 3, 2026, 15:31

SiYuan below v3.7.4 has authorization flaw rated 8.7

A missing authorization vulnerability (CWE-862) with a CVSS score of 8.7 affects the SiYuan note-taking app before v3.7.4. Seventeen endpoints in kernel/api/block.go lack publish-access and role checks, letting anonymous users read private notes and map workspace structure. The flaw is fixed in v3.7.4.

SiYuan below v3.7.4 has authorization flaw rated 8.7
#SiYuan
Read next
Security

mySCADA myPRO Manager: Two Missing-Authorization Flaws in an ICS Management Platform

Security

CISA: Monta EV charging platform has four flaws, worst rated CVSS 9.4

Security

Mooncake flaws rated up to 9.8 allow unauthenticated memory read/write

Security

LXD hit by three critical flaws rated up to 9.9