Impact
SiYuan versions before 3.7.4 contain an authorization flaw in the /api/ref/refreshBacklink endpoint. The flaw allows any anonymous user to invoke the endpoint with a supplied block ID, causing the server to perform persistent writes. This bypasses read‑only protections and can be used for resource amplification attacks, potentially leading to unauthorized data modification and exhaustion of server resources.
Affected Systems
Siyuan (siyuan-note:siyuan) – all releases prior to version 3.7.4 are affected. No further sub‑version details are provided.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending unauthenticated requests to the endpoint, thereby triggering server‑side writes and enabling resource‑amplification attacks.
OpenCVE Enrichment