CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68585

mediumCVSS 5.8covered by 1 sourcefirst seen 2026-08-03
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.

⚡ Watch CVE-2026-68585

Get an email if CVE-2026-68585 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-68585

CVE.org record

Embed the live status

CVE-2026-68585 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68585 status](https://www.csirts.com/badge/CVE-2026-68585)](https://www.csirts.com/cve/CVE-2026-68585)