Impact
SiYuan versions prior to 3.7.4 expose a flaw in eight publish-mode reader‑facing endpoints that incorrectly apply the visibility list instead of the disabled list when filtering results. This defect allows anonymous visitors to discover and read documents that should be hidden from public view, thereby violating confidentiality. The vulnerability is a typical in‑direct authorization failure and is formally categorized as CWE‑863.
Affected Systems
The flaw affects the SiYuan note-taking application, specifically the version range below v3.7.4. Anyone running an affected version of this product, regardless of installation environment, is potentially exposed.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity. No EPSS score is currently published and the issue is not listed in the CISA KEV catalog, implying that widespread exploitation may not yet be documented. However, because the flaw can be triggered by unauthenticated users through standard HTTP endpoints, the attack surface is large and the likelihood remains significant for attackers seeking to harvest hidden content.
OpenCVE Enrichment