Impact
SiYuan versions prior to 3.7.3 allow an attacker to craft paths through the unvalidated avID parameter in all attribute‑view read endpoints. This unsanitized input enables path traversal, letting an attacker read arbitrary JSON files located outside the intended attribute‑view directory. If the attacker can read those files, they may disclose cross‑scope database content, effectively leaking sensitive configuration or user data.
Affected Systems
The vulnerability affects the Siyuan Note client. All releases before version 3.7.3 are susceptible; newer releases contain the fix.
Risk and Exploitability
The CVSS score of 8.3 signals high exploitability and impact. While the EPSS score is not provided, the lack of mitigation means the threat remains significant. The vulnerability is not listed in CISA KEV, indicating no known large-scale exploitation yet. Attackers can target the attribute‑view endpoints remotely; authenticated users with Reader role or anonymous traffic when publish authentication is disabled can leverage the flaw, giving the attacker access to files outside the permitted directory.
OpenCVE Enrichment