Impact
SiYuan Note versions prior to 3.8.2 contain a flaw in the getAttributeViewKeys endpoint that does not filter private attribute‑view cell values. Publish readers can retrieve hidden KeyValues payloads from rows that belong to documents they normally cannot access, exposing private database content despite lacking proper authorization. The vulnerability leads to a direct confidentiality breach, revealing data that should remain restricted to privileged users.
Affected Systems
All releases of SiYuan Note before version 3.8.2 are affected, regardless of the operating system or deployment method. The flaw applies to the Siyuan product supplied by Siyuan‑Note and is identified by the vendor name "siyuan‑note" in the CPEs.
Risk and Exploitability
The reported CVSS score of 7.1 classifies the issue as moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is remote, via the publicly exposed HTTP API, requiring only publish‑read permissions, which makes the impact relevant to any user with that role who can interact with the server.
OpenCVE Enrichment