Impact
SiYuan versions before 3.7.4 contain a flaw in the resolveAssetPath endpoint that fails to enforce proper authorization for CheckAuth‑only requests. When an attacker supplies a relative asset path—one that can be gleaned from published documents—the endpoint returns the full absolute filesystem path unchanged. The disclosure reveals the operating‑system username and the installation directory layout, thereby leaking confidential information about the server’s environment and facilitating further reconnaissance.
Affected Systems
The impacted product is the SiYuan Note desktop application. All releases prior to version 3.7.4 are vulnerable; users running older builds without the update are at risk.
Risk and Exploitability
The CVSS score of 6.9 categorizes the issue as moderate severity. No EPSS score is reported. The vulnerability requires no authentication for the CheckAuth‑only request, and attackers can invoke the endpoint by accessing a publicly readable document or crafting a targeted API call. This suggests a realistic exploitation likelihood for a determined adversary. The issue is not listed in the CISA KEV catalog, indicating no confirmed exploitation at the time of reporting. Based on the description, the likely attack vector is remote delivery via the resolveAssetPath endpoint using harvested relative paths.
OpenCVE Enrichment