A vulnerability labeled as problematic has been found in SiYuan-Note SiYuan up to 3.7.3 . This affects an unknown part of the component ResolveAssetPath Endpoint . Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-72802 . The attack can be launched remotely. No exploit exists. The affected component should be upgraded.