PT-2026-72010 · Siyuan · Siyuan
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An information disclosure issue exists in the 'getAttributeViewBacklinks' endpoint. The system incorrectly consults the forbidden access list instead of the visibility list when filtering backlinks. This allows anonymous readers to provide a publicly visible database row identifier to discover hidden-tier documents that reference it, exposing the database name, row title, and document path of those hidden documents.
Recommendations
Update SiYuan to version 3.7.4 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan