Impact
The vulnerability allows unauthenticated disclosure of confidential document content via the getBlockDOMWithEmbed and getBlockDOMsWithEmbed API endpoints. Because embedded blocks are not filtered by publish access, an attacker can fetch blocks that reference password‑protected, hidden or forbidden documents and obtain their raw text. This results in a confidentiality breach where sensitive data becomes accessible to anyone who can send requests to the exposed API.
Affected Systems
SiYuan applications prior to version 3.7.4 are impacted. Users running any earlier release of the Siyuan note editor should assume their instance is vulnerable. The problem exists in all distributions of the product bundled with the published endpoints, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 9.2 classifies the flaw as critical. The EPSS score is not available, but the lack of exploitation markers and its presence in public advisories suggest a high likelihood of abuse. The attack can be carried out remotely by constructing a request to the exposed API endpoints; authentication is not required, just knowledge of the block identifiers. Because the vulnerability is enumerated in a public advisory and is not listed in CISA KEV, it remains a significant risk that an attacker can read private data from any published document that contains embedded block references.
OpenCVE Enrichment