Impact
The vulnerability resides in the authFilePublishAccess endpoint of SiYuan and permits an unauthenticated user to perform unlimited brute‑force attempts against per‑notebook publish passwords. Because no rate limiting or CAPTCHA is enforced, an attacker can rapidly enumerate password guesses until the correct one is found, granting them read access to the notebook’s contents. This compromises the confidentiality of the stored data at the notebook level, and if the notebook contains sensitive information, the potential damage is significant.
Affected Systems
SiYuan is affected when running versions prior to 3.7.4. The CNA vendor/product name identifies the product as Siyuan Note. No specific sub‑firmware or component versions are listed beyond the 3.7.4 cutoff. These versions are deployed widely in environments that publish notebooks for external sharing.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as High, indicating that the risk of successful exploitation is substantial if attackers can reach the exposed endpoint. The EPSS score is not available, so the current exploitation probability cannot be quantified from that metric. The flaw is not listed in the CISA KEV catalog at present, so there is no record of known widespread exploitation. Nonetheless, because the endpoint allows unauthenticated brute‑forcing without countermeasures, the threat landscape is elevated for any systems where notebook publishing is enabled and exposed to the Internet or an untrusted network.
OpenCVE Enrichment