Description
SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

SiYuan versions prior to 3.8.5 contain a flaw in the /api/notebook/getNotebookInfo endpoint that unintentionally exposes metadata about documents that are excluded from the public publish view. A read‑only or anonymous visitor can request the endpoint for notebooks that are visible on the publish site and receive details such as the number of hidden documents, the total size of these documents, and their modification timestamps. This information disclosure allows an attacker to infer the existence of unpublished or potentially sensitive documents without having direct access to them, potentially aiding further reconnaissance.

Affected Systems

The vulnerability applies to the SiYuan note‑taking application (siyuan‑note:siyuan) released before version 3.8.5. No affected CPE versions are listed beyond the generic b3log:siyuan string, so any deployment of the application that has not been upgraded to 3.8.5 or later is at risk.

Risk and Exploitability

The CVSS score of 6.9 places this flaw in the moderate severity range. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog, indicating that no widespread exploitation has been documented at the time of analysis. Attackers can exploit the weakness from any network location that can reach the API endpoint, typically over HTTP or HTTPS. The vulnerability requires only that the visitor be able to access the publish‑visible notebook and that the read‑only reader password is not set; otherwise, anonymous users can trigger the disclosure.

Generated by OpenCVE AI on October 2, 2026 at 12:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SiYuan application to version 3.8.5 or later to receive the vendor patch that removes the metadata disclosure from the /api/notebook/getNotebookInfo endpoint.
  • If an upgrade is not immediately possible, enforce a reader password for publish‑readers to prevent anonymous users from querying the endpoint.
  • Apply an access control rule or firewall filter that blocks or restricts direct access to the /api/notebook/getNotebookInfo endpoint for unauthenticated or non‑publish users.

Generated by OpenCVE AI on October 2, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.
Title SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo
First Time appeared B3log
B3log siyuan
Weaknesses CWE-200
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:50:33.523Z

Reserved: 2026-10-01T10:39:47.845Z

Link: CVE-2026-103763

cve-icon Vulnrichment

Updated: 2026-10-02T15:49:20.500Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:10.277

Modified: 2026-10-02T16:16:44.620

Link: CVE-2026-103763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:30:20Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor