{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/pdf-processing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-72789"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan","SiYuan (\u003c 3.7.4)","SiYuan (\u003c= 3.7.2)"],"_cs_severities":["critical"],"_cs_tags":["access-control","web-vulnerability","authentication-bypass","information-disclosure","api-security","remote-code-execution","vulnerability","pdf-processing","credential-access","web-application"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eSiYuan versions before 3.7.4 contain a critical authentication bypass vulnerability (CVE-2026-72789) within the application's publish API. The defect stems from an improper access control validation logic where encrypted notebooks are incorrectly treated as publicly accessible by default. When a user has unlocked an encrypted notebook, the application fails to verify the requestor's authorization, enabling anonymous remote users to enumerate and exfiltrate decrypted document content. This flaw allows attackers to bypass intended security boundaries without possessing the necessary encryption keys. Defenders should prioritize updating to v3.7.4 or later to remediate this improper authorization, which significantly exposes sensitive notebook data to unauthorized disclosure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of sensitive, encrypted document content. Any notebook that has been unlocked by a user becomes vulnerable to retrieval by unauthenticated parties through the publish API. This impacts all SiYuan deployments currently running versions earlier than 3.7.4 that utilize the notebook publishing feature.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all SiYuan instances to version 3.7.4 or later immediately to patch the access control flaw.\u003c/li\u003e\n\u003cli\u003eAudit webserver access logs for high volumes of unexpected GET requests to the publish API endpoints from unauthorized IP addresses.\u003c/li\u003e\n\u003cli\u003eDisable the publish API feature temporarily if an immediate update to v3.7.4 is not feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T22:21:37Z","date_published":"2026-08-12T20:54:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/","summary":"SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.","title":"Authentication Bypass in SiYuan Publish API","url":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Pdf-Processing","version":"https://jsonfeed.org/version/1.1"}