Impact
SiYuan versions up to 3.8.4 allow read‑only token holders to bypass publish access control by calling the getDynamicIcon endpoint with type=8 and crafted content. This flaw permits attackers to retrieve block titles, names, aliases, and hierarchical paths of documents that should be protected, effectively leaking sensitive metadata. The vulnerability is an example of insufficient access control (CWE‑862) and can lead to unauthorized disclosure of organization structure or confidential document identities.
Affected Systems
Affected software is Siyuan Note, a note‑taking application, versions through 3.8.4. The vulnerability resides in the dynamic icon handling routine accessed via the public API endpoint /api/getDynamicIcon. End‑users running these versions, especially those that expose read‑only tokens over a network, are at risk.
Risk and Exploitability
The reported CVSS score is 5.3, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely by sending crafted requests to the icon endpoint with a valid read‑only token, so the risk is moderate for environments that expose the API to untrusted users. Proper access checks are missing, making the condition straightforward once a token is obtained.
OpenCVE Enrichment