Impact
The vulnerability in SiYuan releases prior to v3.7.4 allows an attacker who has no authentication to call the getConf endpoint and retrieve sensitive configuration data. The information exposed includes the administrator’s open documents, search terms, notebook paths, and private asset locations. This leads to a confidentiality breach of data that the administrator considers private, but the system’s access control incorrectly permits unauthenticated viewers to read it. The root weakness is a misconfiguration of access control logic (CWE-863).
Affected Systems
SiYuan Note – the desktop and electron application called Siyuan – is affected in all releases before v3.7.4. Any deployment of those earlier versions, regardless of operating system, is vulnerable to the disclosed disclosure. The vulnerability remains until version 3.7.4 or later, which includes the fix for the UILayout filter.
Risk and Exploitability
The CVSS score of 6.9 denotes a moderate severity. Because the exploit requires only a simple HTTP request to an unprotected endpoint, the risk of exploitation is high in environments where the application is exposed to the internet or an untrusted network. EPSS data is not available, but the absence of an EPSS entry does not eliminate potential exploitation. The vulnerability is not listed in CISA KEV, yet its impact on confidentiality coupled with the ease of triggering the path makes it a critical concern that should be remedied promptly.
OpenCVE Enrichment