CVE-2026-74903 | siyuan-note SiYuan up to 3.7.3 BlockDOM Endpoint /api/lute/spinBlockDOM access control

SecurityVulns

A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.3. The affected element is an unknown function of the file /api/lute/spinBlockDOM of the component BlockDOM Endpoint. Executing a manipulation can lead to improper access controls.

This vulnerability is registered as CVE-2026-74903. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More