PT-2026-67403 · Siyuan · Siyuan
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.3
Description
Insufficient publish-access filters are applied to the content endpoints '/api/ref/getBacklinkDoc' and '/api/ref/getBackmentionDoc'. While backlink list endpoints correctly filter documents forbidden from being published, these specific content endpoints only require authentication via
CheckAuth. This allows a reader in publish-mode, including anonymous users if Basic Auth is disabled, to directly access these endpoints using a forbidden document's ID. Consequently, an attacker can retrieve the rendered DOM content of the document and use it as a reference-existence oracle to determine if the document references a specific block.Recommendations
Update SiYuan to version 3.7.3 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan