CVE-2026-72802: Siyuan-Note Siyuan

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout.

Affected products

Published 2026-08-12. Last modified 2026-08-26.