CVE-2026-74904 | siyuan-note SiYuan up to 3.7.3 Block Endpoints kernel/api/block.go getRefText/checkBlockExist/getBlockBreadcrumb improper authorization

SecurityVulns

A vulnerability marked as problematic has been reported in siyuan-note SiYuan up to 3.7.3. Affected by this issue is the function getRefText/checkBlockExist/getBlockBreadcrumb of the file kernel/api/block.go of the component Block Endpoints. The manipulation leads to improper authorization.

This vulnerability is referenced as CVE-2026-74904. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More