CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.7.4 are vulnerable due to inadequate enforcement of publish-access checks in specific API endpoints, allowing unauthorized retrieval of sensitive block attributes from protected documents. This could lead to exposure of critical information such as names, aliases, memos, and custom fields. Organizations using affected versions should prioritize patching to mitigate potential data leaks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.