A vulnerability was found in siyuan-note SiYuan up to 3.7.3. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component pprof. This manipulation of the argument mode causes information disclosure.

This vulnerability is tracked as CVE-2026-74799. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.