Impact
SiYuan before version 3.8.5 contains an information disclosure flaw that permits an attacker to retrieve password‑protected or publish‑disabled rows from a database view via the /api/export/preview endpoint. The vulnerability is a lack of authorization enforcement (CWE‑862). An attacker can request an export preview of a public document that embeds a database view, and then receive the primary‑key text and cell values of rows that should remain hidden, thereby leaking sensitive data.
Affected Systems
The note‑taking application Siyuan, produced by Siyuan‑Note, is affected. Any installation running a version older than 3.8.5 is vulnerable when configured to allow public documents with database views. No other product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 marks this flaw as high severity. EPSS data is not available, and it does not appear in the CISA KEV catalog. The vulnerability can be abused remotely by sending an HTTP request to the /api/export/preview endpoint of a publicly accessible document, so the attack surface is all users with network access to the instance. Once exploited, an attacker gains read access to otherwise protected database rows.
OpenCVE Enrichment