CVE-2026-59853: Siyuan-Note Siyuan

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths, notebook, document, and block IDs, and search and replace keywords for unpublished documents. This issue is fixed in versions 3.7.1.

Affected products

Published 2026-07-09. Last modified 2026-07-10.