Impact
Siyuan does not enforce publish‑access checks when generating rendered output for the /api/export/preview and /api/lute/copyStdMarkdown endpoints. When a public document contains embed queries that reference private, hidden, or publish‑disabled blocks, an attacker who can read the public document can trigger these endpoints and obtain the full rendered content of those sensitive blocks. This flaw is a classic information‑exposure through improper permissions problem, classified as CWE-639.
Affected Systems
The vulnerability affects all instances of Siyuan Note from the open‑source releases prior to version 3.8.2. Any deployment that exposes the affected API endpoints, irrespective of network location, is susceptible if it hosts public documents that embed references to restricted content.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity and the lack of a published EPSS score leaves the exact exploitation probability uncertain, but the flaw is readily exploitable via normal HTTP requests to the vulnerable endpoints. Because the flaw merely leaks content and does not provide execution or persistence capabilities, it is not listed in the CISA KEV catalog, yet it represents a serious confidentiality risk for organizations relying on private or hidden blocks for sensitive data.
OpenCVE Enrichment