CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.7.4 are vulnerable to an information disclosure flaw in the resolveAssetPath endpoint, which exposes absolute filesystem paths in response to CheckAuth-only requests. This vulnerability allows attackers to exploit relative asset paths from published documents to retrieve sensitive server information, including the operating-system username and installation structure. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access to sensitive filesystem details.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout.