A vulnerability marked as problematic has been reported in siyuan-note SiYuan up to 3.7.2. This vulnerability affects unknown code of the file /api/asset/getFileAnnotation of the component FileAnnotation. The manipulation leads to information disclosure.

This vulnerability is listed as CVE-2026-72808. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.