Impact
SiYuan versions prior to 3.7.4 allow attackers with publish reader tokens or anonymous access in disabled-auth mode to read templates, snippets, and export artifacts by directly accessing static routes that do not honor the same publish‑access restrictions applied to the REST API. This results in unauthorized data disclosure because sensitive content can be accessed without proper authentication or authorization checks.
Affected Systems
The vulnerability affects the SiYuan note‑taking application produced by siyuan-note. Versions earlier than 3.7.4 contain the flaw; the static routing logic bypasses the publish‑access controls in place for REST endpoints.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, so the precise exploitation likelihood cannot be quantified, but since the flaw is reachable by anyone with publish‑reader privileges or in anonymous mode, it poses a tangible risk. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the bypass by sending requests to the vulnerable static‑route URLs, avoiding the authentication checks that normally protect the REST API.
OpenCVE Enrichment