Impact
Siyuan versions before 3.7.4 contain a path traversal flaw in the getUniqueFilename endpoint that permits anonymous readers to supply arbitrary absolute paths. The lack of validation lets an attacker probe the host’s file system, determining the existence of files and directories and thereby gathering reconnaissance about installed software and system layout. The weakness is a missing authorization issue (CWE-862) and its primary consequence is the disclosure of sensitive location data, which may be leveraged for subsequent attacks.
Affected Systems
All installations of SiYuan Note software running versions earlier than 3.7.4 are vulnerable. The affected vendor is Siyuan Note and the product is Siyuan.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. EPSS data is not available, and the issue is not listed in CISA KEV. The likely attack vector is remote exploitation, with any user who can reach the getUniqueFilename endpoint able to perform file system enumeration without authentication. Because the endpoint accepts absolute paths indiscriminately, an attacker can confirm the presence of files and directories, revealing the system’s layout and installed software.
OpenCVE Enrichment