CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.7.4 are susceptible to an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint, which lacks proper access controls. This flaw allows attackers to retrieve block identifiers from restricted documents by exploiting publicly visible annotation identifiers, potentially exposing sensitive citation relationships. Organizations using SiYuan should prioritize patching to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.