SiYuan <= 0.0.0-20260313024916-fd6526133bb3 Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- siyuan (go)
- Affected versions
- <= 0.0.0-20260313024916-fd6526133bb3
- Patched version
- v3.7.4
An early warning has been issued for a vulnerability in SiYuan versions before v3.7.4 that may allow unauthorized access to sensitive documents.
What happened
SiYuan versions before v3.7.4 reportedly fail to filter embedded block content by publish access. This vulnerability may allow unauthorized access to password-protected, hidden, or forbidden documents. The issue is under investigation and has not yet been exploited in the wild.
The vulnerability affects the siyuan (go) component with versions less than or equal to 0.0.0-20260313024916-fd6526133bb3. The vulnerability is tracked under GHSA-CJWM-9H7G-PCR9 and GHSA-H6W7-XXCF-W2MQ.
What to do about it
- Upgrade to SiYuan v3.7.4 or later to mitigate the risk of unauthorized access to sensitive documents.
- Review your SiYuan deployment to identify any instances where embedded block content may be exposed without proper access controls.
- Monitor the primary sources for updates on this vulnerability and any additional mitigation steps that may be recommended.
How 0Day would have caught this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using SiYuan versions before v3.7.4 or siyuan (go) versions less than or equal to 0.0.0-20260313024916-fd6526133bb3.
What should I do right now?
Upgrade to SiYuan v3.7.4 or later and review your deployment for any instances where embedded block content may be exposed without proper access controls.
Has this been exploited in the wild?
No, this vulnerability has not yet been exploited in the wild.