Impact
The vulnerability in SiYuan versions before 3.7.4 allows an unauthenticated user to call the getGraph and getLocalGraph endpoints without a publish‑password tier. The service fails to enforce password protection, enabling attackers to retrieve the block‑level content of protected documents and the full reference topology. This flaw results in a confidentiality breach, exposing sensitive information and internal document structure, and is identified as a CWE‑200 information disclosure weakness.
Affected Systems
SiYuan Note is affected for all releases prior to version 3.7.4. Any instance of SiYuan that has not been updated to 3.7.4 or later is vulnerable and may be accessed by anonymous users through the exposed graph endpoints.
Risk and Exploitability
The CVSS score of 9.2 classifies the flaw as critical. Because the attack requires only a simple HTTP request to the public endpoints and no authentication, the exploitation likelihood is high despite the EPSS score being unavailable. The vulnerability is not listed in CISA KEV, but the impact and ease of exploitation warrant urgent attention. An attacker could easily harvest confidential document content by simply sending GET requests to the vulnerable endpoints.
OpenCVE Enrichment