Impact
The vulnerability is a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints of SiYuan. Attackers with read‑only or anonymous publish access can POST any open notebook ID and obtain the global save‑box ID and save‑path template. This disclosure reveals the existence and creation time of notebooks that are otherwise hidden, exposing sensitive information about unpublished content.
Affected Systems
Siyuan Note’s SiYuan application, affecting all installations of the product running any version prior to v3.8.5.
Risk and Exploitability
The CVSS score of 6.9 reflects a medium severity with a moderate likelihood of exploitation. Because the affected endpoints are accessible over the network and only require read‑only or anonymous access, the attack vector is easily reachable by external actors. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently a high‑profile target. Nonetheless, the data exposed is non‑public notebook metadata, which may be valuable to attackers seeking to map or target unused content.
OpenCVE Enrichment