Impact
The vulnerability allows anonymous readers to access content that should have been hidden, through SQL embed blocks, attribute-view keys, and attribute-view backlinks enabled in publish mode. The failure to filter invisible-tier content permits the disclosure of sensitive data, reducing confidentiality and potentially revealing private information to unauthenticated users. This weakness is categorized as CWE-668, indicating an information exposure flaw.
Affected Systems
Siyuan Note (siyuan-note:siyuan) is affected by all releases before version 3.8.1. Administrators who have marked content as unlisted may still expose it when publishing documents.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability presents moderate risk. An attacker does not need authentication; any anonymous reader can exploit the flaw simply by accessing a published URL. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. However, the ease of exploitation and lack of access control makes it a low‑effort disclosure risk for exposed data.
OpenCVE Enrichment