CVE-2026-68585 | siyuan-note siyuan up to 3.7.2 BlockInfo Endpoint /api/block/getBlockInfo block_id information disclosure

SecurityVulns

A vulnerability, which was classified as problematic, was found in siyuan-note siyuan up to 3.7.2. This issue affects some unknown processing of the file /api/block/getBlockInfo of the component BlockInfo Endpoint. Executing a manipulation of the argument block_id can lead to information disclosure.

This vulnerability is handled as CVE-2026-68585. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More