medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-105205
SiYuan versions prior to 3.8.5 allow publish‑mode readers to retrieve backlink block IDs and reference counts from password‑protected or pub
Overview
SiYuan versions prior to 3.8.5 allow publish‑mode readers to retrieve backlink block IDs and reference counts from password‑protected or publish‑disabled documents via API calls. This exposes hidden metadata that should remain confidential. The flaw is exploitable by sending POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID.
Description
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.
Impact
Confidentiality is compromised: attackers can discover internal block identifiers and reference counts that are not intended for public view. This may aid in mapping document structure or identifying sensitive content. Defenders using SiYuan for knowledge management, especially with publish mode enabled, are at risk.
Remediation
Upgrade SiYuan to version 3.8.5 or later to eliminate the vulnerability. Until patching, disable publish mode for sensitive documents or remove password protection from documents that must remain private. Restrict API access by firewall rules or authentication, and monitor logs for unexpected POST requests to /api/block/getDocInfo or getDocsInfo.
Risk context
The CVSS v3 score of 5.3 and v4 score of 6.9 classify this as medium severity. With no EPSS data, the risk remains moderate; timely patching is recommended but not urgent.
Affected products
- SiYuan 3.8.x
- SiYuan 3.7.x
- SiYuan 3.6.x
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —