{"id":"CVE-2026-68585","aliases":["GHSA-pm3w-vxp9-ccwc"],"url":"https://o3.security/vulnerability/CVE-2026-68585","summary":"SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo","details":"SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.","published":"2026-08-03T13:20:37.134Z","modified":"2026-08-28T11:30:15.969051836Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/siyuan-note/siyuan/kernel","fixedVersion":"0.0.0-20260721014951-ffde3b21eca4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68585.json"},{"type":"ADVISORY","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68585"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/siyuan-before-metadata-disclosure-via-getblockinfo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T11:30:15.969051836Z"}}