Critical Vulnerability in SiYuan Note-Taking Application Allows Unauthorized Content Disclosure (CVE-2026-68586)
A critical vulnerability (CVE-2026-68586) with a CVSS score of 8.6 affects the SiYuan note-taking application before version 3.7.3. The vulnerability allows a publish-mode reader, including anonymous readers, to retrieve rendered DOM content of publish-forbidden documents and determine if a document references a given block. Immediate patching to version 3.7.3 or later is recommended.