Impact
SiYuan versions before 3.7.4 have a flaw in the getRefIDsByFileAnnotationID endpoint that returns block identifiers referencing PDF annotations without applying publish‑access filtering. An attacker can provide annotation identifiers that are exposed on publicly accessible pages and obtain the block identifiers that cite those annotations inside documents that are otherwise restricted or password‑protected. This reveals citation relationships between documents, exposing which files are referenced by others and thereby compromising confidentiality.
Affected Systems
The vulnerable product is SiYuan by the vendor siyuan-note. All releases earlier than version 3.7.4 are affected; no other products or versions are listed as impacted in the current advisory.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity. EPSS information is not available, so the exploitation probability cannot be quantified, and the vulnerability is not present in CISA KEV. The endpoint is reachable over HTTP(s); it does not mention that authentication is required, so it is inferred that the endpoint may be accessible without prior authentication, making the attack network‑based and potentially publicly discoverable. Exploitation does not require privilege escalation or additional resources beyond the ability to supply a valid annotation identifier. The impact is limited to disclosure of internal document relationships rather than code execution or service disruption.
OpenCVE Enrichment