CyberRota Analysis
AI-GeneratedAn information disclosure vulnerability exists in SiYuan versions prior to 3.7.4, allowing unauthenticated users to access tag labels and occurrence counts from password-protected documents via the /api/tag/getTag endpoint. This can lead to the enumeration of sensitive tag vocabulary and internal terminology, potentially exposing confidential information. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.