CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.7.4 are vulnerable due to inadequate validation of the publish-password tier in the getGraph and getLocalGraph endpoints, enabling unauthorized access to block-level content in password-protected documents. This flaw allows anonymous users to retrieve sensitive information without authentication, posing a significant risk to data confidentiality. Organizations using affected versions should prioritize patching to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.