CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.7.3 are vulnerable to a metadata disclosure issue in the /api/block/getBlockInfo endpoint, allowing unauthorized users to access sensitive document metadata, including titles and paths of documents marked as non-publishable. This vulnerability could lead to information leakage, potentially exposing sensitive content to unauthorized individuals. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.