CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated attackers to exploit the /api/system/uiproc endpoint in SiYuan versions prior to 3.8.2, where they can submit unlimited attacker-controlled process identifiers. This can lead to a denial of service by exhausting process memory, significantly degrading service availability. Organizations using affected versions should prioritize patching to mitigate the risk of service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.