Impact
SiYuan versions before 3.7.4 contain an authentication bypass in the FilterViewByPublishAccess filter that skips checking the publish password when rendering attribute views and database rows. Unauthenticated users can call the renderAttributeView endpoint without supplying the required password and thereby read password‑protected document rows—including titles, block identifiers and column values—resulting in unauthorized disclosure of sensitive data. This weakness is a missing authorization flaw (CWE‑862).
Affected Systems
The affected product is the SiYuan note application (siyuan). All releases prior to v3.7.4 are vulnerable; no further version detail is provided in the CVE record.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in CISA KEV, but it can be exploited remotely by sending an unauthenticated request to the renderAttributeView API endpoint. The attack requires no special privileges, the complexity is low, and it can lead to the disclosure of protected content.
OpenCVE Enrichment