Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.
Published: 2026-08-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions before 3.7.4 have a flaw in the getRefIDsByFileAnnotationID endpoint that returns block identifiers referencing PDF annotations without applying publish‑access filtering. An attacker can provide annotation identifiers that are exposed on publicly accessible pages and obtain the block identifiers that cite those annotations inside documents that are otherwise restricted or password‑protected. This reveals citation relationships between documents, exposing which files are referenced by others and thereby compromising confidentiality.

Affected Systems

The vulnerable product is SiYuan by the vendor siyuan-note. All releases earlier than version 3.7.4 are affected; no other products or versions are listed as impacted in the current advisory.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity. EPSS information is not available, so the exploitation probability cannot be quantified, and the vulnerability is not present in CISA KEV. The endpoint is reachable over HTTP(s); it does not mention that authentication is required, so it is inferred that the endpoint may be accessible without prior authentication, making the attack network‑based and potentially publicly discoverable. Exploitation does not require privilege escalation or additional resources beyond the ability to supply a valid annotation identifier. The impact is limited to disclosure of internal document relationships rather than code execution or service disruption.

Generated by OpenCVE AI on August 14, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.7.4 or later where the getRefIDsByFileAnnotationID endpoint enforces proper publish‑access filtering.
  • After patching, verify that the endpoint no longer returns unrestricted block identifiers and that publish‑access controls function correctly.
  • If an immediate upgrade is not feasible, restrict access to the getRefIDsByFileAnnotationID endpoint to authenticated users with appropriate publish privileges through firewall rules or reverse‑proxy authentication checks.

Generated by OpenCVE AI on August 14, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared B3log
B3log siyuan
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan

Fri, 14 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Fri, 14 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.
Title SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T18:01:01.022Z

Reserved: 2026-08-10T19:06:03.365Z

Link: CVE-2026-73048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-14T12:16:47.567

Modified: 2026-08-26T16:57:52.167

Link: CVE-2026-73048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T13:45:16Z

Weaknesses