CVE-2026-72812: Siyuan-Note Siyuan
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, bypassing read-only protections and enabling resource amplification attacks.
Affected products
- Siyuan-Note Siyuan: before 3.7.4 (fixed in 3.7.4)
Published 2026-08-14. Last modified 2026-08-26.