0day Signal@0dayPublishingDisclosure
SiYuan’s publishing service is vulnerable to CVE-2026-33669, allowing arbitrary document enumeration and content exfiltration through specific API endpoints, as detailed in the linked zero days report.
PulsePatch.io@pulsepatchioPatch
The text announces CVE‑2026‑33669 as an arbitrary document reading flaw in SiYuan and recommends restricting access configurations as a mitigation.
The Hacker Wire@TheHackerWireDisclosure
A critical CVE-2026-33669 was disclosed for SiYuan, highlighting that document IDs were exposed via the /api/file/readDir and /api/block/getChildBlocks interfaces prior to the 3.6.2 update.
CVEFind.com@CveFindComPatch
The CVE-2026-33669 vulnerability exposed document IDs and content in earlier SiYuan versions, but the issue has been patched in release 3.6.2, with no evidence of active exploitation or PoC.
CVE@CVEnewDisclosure
The text merely discloses that SiYuan versions prior to 3.6.2 allow document IDs to be retrieved through specific API endpoints, with no evidence of a Proof of Concept, exploit code, or active exploitation.