Impact
SiYuan versions prior to 3.8.5 contain a flaw in the /api/notebook/getNotebookInfo endpoint that unintentionally exposes metadata about documents that are excluded from the public publish view. A read‑only or anonymous visitor can request the endpoint for notebooks that are visible on the publish site and receive details such as the number of hidden documents, the total size of these documents, and their modification timestamps. This information disclosure allows an attacker to infer the existence of unpublished or potentially sensitive documents without having direct access to them, potentially aiding further reconnaissance.
Affected Systems
The vulnerability applies to the SiYuan note‑taking application (siyuan‑note:siyuan) released before version 3.8.5. No affected CPE versions are listed beyond the generic b3log:siyuan string, so any deployment of the application that has not been upgraded to 3.8.5 or later is at risk.
Risk and Exploitability
The CVSS score of 6.9 places this flaw in the moderate severity range. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog, indicating that no widespread exploitation has been documented at the time of analysis. Attackers can exploit the weakness from any network location that can reach the API endpoint, typically over HTTP or HTTPS. The vulnerability requires only that the visitor be able to access the publish‑visible notebook and that the read‑only reader password is not set; otherwise, anonymous users can trigger the disclosure.
OpenCVE Enrichment