Impact
SiYuan versions prior to 3.7.4 contain a flaw in the /getBookmarkLabels endpoint that returns the full list of bookmark labels in a workspace. The response includes labels from all documents, bypassing the publish‑access filter. Therefore, an attacker, even without additional credentials, can learn the naming convention and organization of bookmarks, which in many cases reveals subject matter and organizational structure of otherwise restricted documents.
Affected Systems
The vulnerable software is SiYuan, the knowledge‑management application, for all releases before 3.7.4. Users of earlier builds should verify their install version and consider upgrading to 3.7.4 or later, which removes the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, but the vulnerability is exploitable by anyone with read access to the workspace, including anonymous or publish‑mode readers, without any authentication or privilege escalation. Because the flaw leaks only metadata and not full document contents, the attack vector is limited to information disclosure; privacy and reputational impacts result from exposing content organization across the workspace. The issue is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment