CVE-2026-68585 | siyuan-note siyuan up to 3.7.2 BlockInfo Endpoint /api/block/getBlockInfo block_id information disclosure
A vulnerability, which was classified as problematic, was found in siyuan-note siyuan up to 3.7.2. This issue affects some unknown processing of the file /api/block/getBlockInfo of the component BlockInfo Endpoint. Executing a manipulation of the argument block_id can lead to information disclosure.
This vulnerability is handled as CVE-2026-68585. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More