Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. Unauthenticated attackers or publish readers can retrieve closed-tab history, search keywords, private document identifiers, and expanded folder paths by calling the getLocalStorage endpoint. | |
| Title | SiYuan before v3.7.4 Information Disclosure via Local Storage | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T12:51:08.193Z
Reserved: 2026-08-13T11:15:12.096Z
Link: CVE-2026-73610
Updated: 2026-08-13T12:51:03.884Z
Status : Received
Published: 2026-08-13T12:17:25.607
Modified: 2026-08-13T13:19:19.397
Link: CVE-2026-73610
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:20:10Z
-
CWE-639
Authorization Bypass Through User-Controlled Key