rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9

CVE-2026-103762

SiYuan before v3.8.5 has a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints

Overview

SiYuan before v3.8.5 has a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read‑only or anonymous publish visitors to discover unpublished notebook box IDs and their creation times. Attackers can POST any open notebook ID to receive the global save‑box ID and save‑path template, revealing hidden notebooks. The vulnerability does not modify data but exposes sensitive metadata.

Description

SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.

Impact

Confidentiality: Unpublished notebook IDs and creation timestamps are exposed to anyone with read‑only or anonymous publish access. Integrity: No direct modification of data, but knowledge of IDs could facilitate further attacks. Availability: No impact. Defenders: Users of SiYuan with public or read‑only publish settings.

Remediation

Upgrade to SiYuan v3.8.5 or later. If an upgrade is not immediately possible, restrict or disable read‑only/anonymous publish access, or block the affected endpoints via a firewall or reverse proxy.

Risk context

Medium severity (CVSS v3 5.3, CVSS v4 6.9). No EPSS data available. Defenders should assess exposure of read‑only publish settings and apply the patch promptly.

Affected products

  • SiYuan

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
—

SiYuan Missing Authorization Notebook ID Disclosure Read-Only Medium Severity

← All CVEs