medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-103762
SiYuan before v3.8.5 has a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints
Overview
SiYuan before v3.8.5 has a missing authorization flaw in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read‑only or anonymous publish visitors to discover unpublished notebook box IDs and their creation times. Attackers can POST any open notebook ID to receive the global save‑box ID and save‑path template, revealing hidden notebooks. The vulnerability does not modify data but exposes sensitive metadata.
Description
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
Impact
Confidentiality: Unpublished notebook IDs and creation timestamps are exposed to anyone with read‑only or anonymous publish access. Integrity: No direct modification of data, but knowledge of IDs could facilitate further attacks. Availability: No impact. Defenders: Users of SiYuan with public or read‑only publish settings.
Remediation
Upgrade to SiYuan v3.8.5 or later. If an upgrade is not immediately possible, restrict or disable read‑only/anonymous publish access, or block the affected endpoints via a firewall or reverse proxy.
Risk context
Medium severity (CVSS v3 5.3, CVSS v4 6.9). No EPSS data available. Defenders should assess exposure of read‑only publish settings and apply the patch promptly.
Affected products
- SiYuan
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —