rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9

CVE-2026-105205

SiYuan versions prior to 3.8.5 allow publish‑mode readers to retrieve backlink block IDs and reference counts from password‑protected or pub

Overview

SiYuan versions prior to 3.8.5 allow publish‑mode readers to retrieve backlink block IDs and reference counts from password‑protected or publish‑disabled documents via API calls. This exposes hidden metadata that should remain confidential. The flaw is exploitable by sending POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID.

Description

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.

Impact

Confidentiality is compromised: attackers can discover internal block identifiers and reference counts that are not intended for public view. This may aid in mapping document structure or identifying sensitive content. Defenders using SiYuan for knowledge management, especially with publish mode enabled, are at risk.

Remediation

Upgrade SiYuan to version 3.8.5 or later to eliminate the vulnerability. Until patching, disable publish mode for sensitive documents or remove password protection from documents that must remain private. Restrict API access by firewall rules or authentication, and monitor logs for unexpected POST requests to /api/block/getDocInfo or getDocsInfo.

Risk context

The CVSS v3 score of 5.3 and v4 score of 6.9 classify this as medium severity. With no EPSS data, the risk remains moderate; timely patching is recommended but not urgent.

Affected products

  • SiYuan 3.8.x
  • SiYuan 3.7.x
  • SiYuan 3.6.x

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
—

information-disclosure SiYuan publish-mode confidentiality API medium-severity

← All CVEs