Sceawere

Vulnerability Detail

CVE-2026-103762UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:09.100Z",
  "pubdate": "2026-10-02T12:17:09.100Z",
  "executiveSummary": "The vulnerability identified in SiYuan prior to version 3.8.5 is a missing authorization flaw located within several backend API endpoints. This security weakness allows unauthenticated or low-privilege 'read-only' publish visitors to perform unauthorized information gathering regarding the system's internal structure.\nSpecifically, the flaw impacts the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints. By interacting with these functions, an attacker can extract sensitive metadata, including global save-box IDs and save-path templates associated with unpublished or hidden notebook configurations.\nThe primary risk involves the unauthorized disclosure of information regarding non-public notebooks, effectively bypassing intended access controls. An attacker can confirm the existence of hidden content and determine its creation timeline without requiring administrative privileges or legitimate notebook access. This flaw exposes structural data that should remain confidential to prevent reconnaissance and potential targeting of private data repositories within the SiYuan environment.\nExploitation does not require elevated privileges, as the vulnerable endpoints fail to validate the session context or authorization level of the requesting user, making the system susceptible to remote attackers with basic publish-mode access.",
  "technicalDetails": "The vulnerability resides in the server-side authorization logic governing specific API endpoints responsible for defining save-path configurations: getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath. In SiYuan versions prior to 3.8.5, these endpoints operate under the assumption that the requestor is an authorized user with legitimate access to the notebook storage structures.\nThe root cause of the vulnerability is the absence of an authorization check (Missing Authorization) within the endpoint handlers. When a request is processed, the backend fails to verify whether the requester possesses the required permissions to access information related to specific notebook box IDs. Consequently, the API treats all incoming POST requests—regardless of the user's role—as legitimate if the request is formatted correctly.\nThe attack flow proceeds as follows: An attacker with read-only access or anonymous access to a published SiYuan instance initiates a POST request to one of the identified vulnerable endpoints. The attacker includes an arbitrary open notebook ID in the request payload. Because the server does not enforce access control, the application processes the request and returns the associated metadata, specifically the global save-box ID and the corresponding save-path template.\nBy iterating through potential notebook IDs or capturing responses from the server, an attacker can identify the existence of notebooks that have not been explicitly published or intended for public view. The payload effectively forces the application to leak metadata about hidden repositories. The information obtained—specifically the creation timestamp and internal structure—allows an attacker to map the internal organization of the SiYuan instance.\nThis vulnerability is classified as a logic flaw where the application's authentication state is disconnected from the endpoint's execution flow. The impact is significant in terms of information disclosure, as it allows for the enumeration of system resources that are supposed to remain opaque to the public. As the endpoints are accessible via standard network protocols, they present a surface for remote exploitation without specialized interaction, relying solely on the application's ability to expose backend identifiers to unauthorized endpoints."
}
CVE-2026-103762: SiYuan Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere