Description
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure through missing authorization of save‑path resolution endpoints
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints of SiYuan. Attackers with read‑only or anonymous publish access can POST any open notebook ID and obtain the global save‑box ID and save‑path template. This disclosure reveals the existence and creation time of notebooks that are otherwise hidden, exposing sensitive information about unpublished content.

Affected Systems

Siyuan Note’s SiYuan application, affecting all installations of the product running any version prior to v3.8.5.

Risk and Exploitability

The CVSS score of 6.9 reflects a medium severity with a moderate likelihood of exploitation. Because the affected endpoints are accessible over the network and only require read‑only or anonymous access, the attack vector is easily reachable by external actors. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently a high‑profile target. Nonetheless, the data exposed is non‑public notebook metadata, which may be valuable to attackers seeking to map or target unused content.

Generated by OpenCVE AI on October 2, 2026 at 12:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SiYuan v3.8.5 or newer, where the missing authorization check has been added.
  • Limit or disable read‑only and anonymous publish permissions for notebooks that contain sensitive or unpublished data until the patch is applied.
  • Configure network controls or a reverse‑proxy to block external access to the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints, allowing only authenticated management traffic.

Generated by OpenCVE AI on October 2, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
Title SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints
First Time appeared B3log
B3log siyuan
Weaknesses CWE-862
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:37:53.531Z

Reserved: 2026-10-01T10:39:47.845Z

Link: CVE-2026-103762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:09.100

Modified: 2026-10-02T12:17:10.190

Link: CVE-2026-103762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses