A vulnerability labeled as problematic has been found in SiYuan-Note SiYuan up to 3.7.3. This vulnerability affects the function getRefIDsByFileAnnotationID of the component getRefIDsByFileAnnotationID endpoint. Such manipulation leads to information disclosure.

This vulnerability is listed as CVE-2026-73048. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.