PT-2026-71235 · Siyuan · Siyuan
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
Sensitive configuration fields are not properly masked in the '/api/system/getConf' endpoint. This allows anonymous users or those with publish-reader permissions to retrieve the session-cookie signing key, the OS username through the pandoc path, and encrypted-notebook key material. An attacker can use this information to forge or tamper with session cookies to impersonate other users. In environments where access-auth codes are not configured, this can lead to a privilege escalation to administrator status.
Recommendations
Update to version 3.7.4 or later.
Restrict access to the '/api/system/getConf' endpoint as a temporary mitigation measure.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan