Impact
The vulnerability in Siyuan before version 3.8.2 allows unauthenticated publish-mode readers to learn whether certain content exists in hidden or unpublished documents by using the POST /api/search/fullTextSearchBlock endpoint. Although the endpoint filters private blocks from returned results, it still exposes the exact number of matching blocks and pages. This enables the attacker to infer the presence and quantity of confidential material.
Affected Systems
The Siyuan note application, distributed by Siyuan Note (vendor siyuan-note:siyuan), is affected in all releases prior to version 3.8.2. Users running any of those earlier builds are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 identifies the flaw as medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation to date. The attack vector requires only unauthenticated access to the publish‑mode web application and the ability to send a POST request to the fullTextSearchBlock endpoint, allowing an adversary to discover the existence and count of hidden content without further privileges.
OpenCVE Enrichment