Impact
The vulnerability is an information disclosure caused by missing publish‑access checks in the getCurrentAttrViewImages endpoint. Attackers who possess publish read permissions can invoke this endpoint with an unrendered database identifier obtained from related endpoints. The server then returns file system paths and filenames for image assets that are otherwise inaccessible to that user, leaking potentially sensitive internal locations and file names.
Affected Systems
The flaw affects Siyuan Note software provided by siyuan-note. All releases prior to version 3.8.4 are vulnerable; the vulnerable behavior is observed in the getCurrentAttrViewImages API.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability, and the EPSS score is not available while the issue is not listed in the CISA KEV catalog. Exploitation requires authenticated access with publish reader role and the ability to supply an unrendered database identifier, meaning it is not a public remote exploit but can be carried out by users who can enumerate databases. Once triggered, the endpoint leaks asset paths and filenames that could assist attackers in mapping internal file structures or planning further attacks. The overall risk is considered moderate; however, impact on confidentiality may be significant in environments where image assets contain proprietary or sensitive data.
OpenCVE Enrichment