Impact
SiYuan before version 3.7.4 suffers from an information disclosure flaw in its local storage filter. The defect allows the server to return the full local storage map of the administrator to any requester through the getLocalStorage endpoint, after sanitizing only three keys. This grants attackers access to closed‑tab history, search keywords, private document identifiers, and expanded folder paths—data that should be protected and not exposed to unauthenticated or read‑only users.
Affected Systems
The vulnerability affects the Siyuan Note application provided by the vendor siyuan-note. All releases prior to v3.7.4 are impacted; users should verify whether they are running v3.7.4 or earlier and plan an upgrade accordingly.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the unfiltered data export exposes potentially sensitive information to unauthenticated attackers or publish‑readers, which may be accessed remotely via the getLocalStorage endpoint. Although EPSS data is not available and the vulnerability is not listed in CISA KEV, the attack vector is likely remote based on the endpoint’s public accessibility. The questionable sanitization means that an attacker could harvest patterns of usage or identify private documents for further exploitation.
OpenCVE Enrichment