PT-2026-72009 · Siyuan · Siyuan
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An information disclosure issue exists in the 'getRefIDsByFileAnnotationID' endpoint. The system returns block identifiers that cite PDF annotations without applying publish-access filtering. This allows attackers to extract block identifiers from restricted documents by providing annotation identifiers visible on published pages, thereby exposing citation relationships across password-protected and forbidden tiers.
Recommendations
Update SiYuan to version 3.7.4 or later.
As a temporary mitigation, restrict access to the 'getRefIDsByFileAnnotationID' endpoint.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan