Impact
SiYuan versions up to and including v3.7.2 contain a flaw in the kernel's CheckAuth function. Requests that originate from the loopback address (127.0.0.1) to a limited set of endpoints—including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/, and /export/—are automatically granted the administrator role (RoleAdministrator), regardless of whether an access authentication code has been configured. This bypass circumvents the normal authorization gate for those endpoints.
Affected Systems
The affected product is SiYuan Note, developed by siyuan-note. Versions up to and including 3.7.2 are impacted. The fix was released in version 3.7.4, which removes the loopback bypass in the CheckAuth function.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, and the vulnerability is listed as not in the CISA KEV catalog. EPSS information is not available, so the current likelihood of exploitation cannot be quantified; however, the advisory notes that a reverse proxy bound to a network interface could forward traffic to the kernel with a RemoteAddr of 127.0.0.1, thereby allowing an unauthenticated remote attacker to obtain administrator access on the affected endpoints. The exploitation scenario has not been reproduced end‑to‑end, so the real‑world risk depends on the presence of such a misconfigured proxy or local access to the host.
OpenCVE Enrichment