Sceawere
Vulnerability Detail
CVE-2026-103763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiYuan Metadata Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.8
- Creation Date
- 11h ago
- Vendor
- siyuan-note
- Product
- siyuan
- Attack Type
- Exposure of Sensitive Information to an Unauthorized Actor
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.8",
"pubDate": "2026-10-02T12:17:10.277Z",
"pubdate": "2026-10-02T12:17:10.277Z",
"executiveSummary": "SiYuan versions prior to v3.8.5 contain an information disclosure vulnerability within the publishing module.\nThe vulnerability allows unauthorized entities, including unauthenticated remote visitors, to retrieve sensitive metadata concerning documents explicitly marked as excluded from public publishing.\nThe flaw manifests in the getNotebookInfo endpoint, which fails to enforce access control constraints for excluded content metadata.\nImpact includes the exposure of document counts, file sizes, and modification timestamps, facilitating reconnaissance against private or restricted internal documentation.\nAttackers can leverage this information to map out sensitive data structures or track document activity without requiring valid credentials, provided the notebook is accessible via the publish-visible interface.\nThe risk is elevated in environments where no reader password is set, effectively enabling anonymous exploitation via standard network requests.",
"technicalDetails": "The vulnerability resides in the server-side logic of the getNotebookInfo API endpoint, which is responsible for returning notebook configuration and statistical data. In affected versions of SiYuan (prior to v3.8.5), the API implementation fails to perform adequate filtering on the returned metadata objects.\nWhen a user or anonymous visitor requests metadata through the getNotebookInfo endpoint, the application retrieves information for the specified notebook. Although the user interface may exclude these documents from the public view, the backend API incorrectly includes the metadata for all documents within the notebook scope, regardless of their 'excluded' status.\nThe attack flow involves an adversary sending a crafted HTTP request to the getNotebookInfo endpoint. Because the endpoint does not adequately differentiate between public and non-public metadata, the server response includes detailed information about restricted documents. This data specifically leaks the total document count, the serialized size of the restricted content, and precise modification timestamps.\nNo authentication is required for this exploitation if the notebook is configured for public access without a reader password. Even if a reader password is required, a user with read-only 'publish reader' privileges can circumvent the intended isolation of hidden content metadata.\nFrom an attacker's perspective, this allows for the reconstruction of organizational activity, document cadence, and content volume for private documents that were intended to remain confidential. By analyzing modification timestamps over time, an attacker can perform traffic and behavioral analysis to infer when sensitive projects are being updated or modified.\nThe vulnerable component is the server-side publishing module responsible for handling metadata aggregation. The failure to implement proper authorization checks on individual document objects prior to serializing the response body represents a fundamental failure in the Principle of Least Privilege and secure data exposure practices."
}