CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.7.4 are vulnerable due to the exposure of key-derivation materials and wrapped data keys through unauthenticated endpoints in publish mode. This flaw allows attackers to access sensitive Argon2id parameters and perform unlimited offline cracking attempts on master passwords, significantly compromising the security of encrypted notebooks. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.