Impact
SiYuan versions prior to 3.7.4 do not enforce proper filtering of related‑database content when rendering attribute views, which allows unauthenticated viewers to access the contents of Relation and Rollup cells that belong to hidden or password‑protected databases. As a result, sensitive data can be disclosed through published databases that reference restricted ones or by bypassing row‑level filtering when the first column is a non‑block type.
Affected Systems
SiYuan Note (siyuan) products running any version earlier than 3.7.4 are affected. The vulnerability manifests when a database is published with relationships pointing to hidden or protected databases, enabling anonymous readers to retrieve restricted cell contents through the renderAttributeView functionality.
Risk and Exploitability
The CVSS score of 9.2 classifies this flaw as critical, and the KEV listing is not present, indicating no widespread exploitation has been recorded yet. The EPSS score is unavailable, so the exact exploit probability cannot be quantified. The likely attack vector is remote, as an attacker only needs network or web access to the running instance to request a published database and trigger the vulnerable renderAttributeView process. No authentication or privileged access is required, so anyone who can reach the service is potentially able to exfiltrate sensitive data.
OpenCVE Enrichment