PT-2026-71237 · Siyuan · Siyuan
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An issue exists where the software fails to filter embedded block content based on publish access permissions. While the initial requested block is checked for authorization, blocks pulled in via embed queries (transclusion) are inlined into the returned DOM without any access checks. This allows an anonymous reader or a user with a publish reader token to read content from documents that are hidden, forbidden, or password-protected, provided they request a legitimately published block that contains an embed query matching those private documents.
API Endpoints:
- '/api/block/getBlockDOMWithEmbed'
- '/api/block/getBlockDOMsWithEmbed'
Vulnerable Parameters or Variables:
idids
Function Names:
resolveEmbedContentInBox()
Recommendations
Update SiYuan to version 3.7.4 or later.
As a temporary workaround, avoid publishing documents that contain embed queries spanning sensitive or password-protected areas of the workspace.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan