Impact
The vulnerability allows unauthenticated users to call the /api/system/getConf endpoint when Siyuan is running in publish mode, resulting in the disclosure of the session cookie signing key. An attacker who obtains this key can create forged session cookies, thereby impersonating any user or gaining administrative privileges.
Affected Systems
The vendor is Siyuan-Note and the product Siyuan. All versions before 3.7.4 are affected, including any prior builds that are running with publish mode enabled.
Risk and Exploitability
The CVSS base score of 9.2 indicates a severe vulnerability. No EPSS score is available, and it is not listed in the CISA KEV catalog. The endpoint is accessible over the network, so the likely attack vector is network-based. Because the secret key is exposed, an adversary can forge session cookies and bypass authentication, potentially compromising user accounts and administrative functions.
OpenCVE Enrichment