Impact
A missing authorization check in the /api/storage/getOutlineStorage endpoint allows an unauthenticated attacker to retrieve the outline state of any document, including heading identifiers, even for documents that are otherwise forbidden. This results in the disclosure of internal document structure and identifiers, which could be leveraged in future attacks that rely on knowing specific document metadata.
Affected Systems
SiYuan Note versions earlier than 3.7.4 are affected by the flaw in the getOutlineStorage API exposed by the application.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting its exploitation risk is currently unproven but non‑negligible. Attackers can exploit the flaw remotely by sending a crafted request to the exposed endpoint without providing credentials. The lack of authorization checks means any client can obtain sensitive document metadata, potentially aiding in social engineering or further compromise. Given the moderate CVSS and the lack of published exploitation, the threat remains moderate but actionable.
OpenCVE Enrichment