Sceawere
Vulnerability Detail
CVE-2026-105205UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiYuan Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 5h ago
- Vendor
- siyuan-note
- Product
- siyuan
- Attack Type
- Exposure of Sensitive Information to an Unauthorized Actor
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-04T15:16:31.350Z",
"pubdate": "2026-10-04T15:16:31.350Z",
"executiveSummary": "An information disclosure vulnerability exists in SiYuan prior to version 3.8.5, stemming from an improper access control implementation within the publishing module. The flaw enables unauthorized users, specifically those with access to published documents, to bypass confidentiality boundaries and retrieve sensitive metadata associated with restricted content.\nThe vulnerability resides in the application's handling of backlink and reference metadata. By interacting with the /api/block/getDocInfo or /api/block/getDocsInfo endpoints, an attacker can extract internal block identifiers (refIDs) and reference counts (refCount) pertaining to documents that are explicitly password-protected or marked as non-publishable. This occurs because the server-side logic fails to validate the authorization status of the requested blocks against the user's current session permissions before returning the query results.\nThis exposure permits an attacker to map the internal structure and inter-dependencies of private documents, potentially revealing document titles or content context through block references. The impact is a breach of information confidentiality, as the system erroneously treats protected document metadata as publicly accessible context. No specific user authentication is required beyond having access to the publicly available interface. Users are advised to upgrade to version 3.8.5 or later to resolve the underlying authorization logic flaw.",
"technicalDetails": "The vulnerability is located in the SiYuan API layer, specifically within the backend controllers responsible for fetching block information. The root cause is a deficiency in the authorization check logic governing the /api/block/getDocInfo and /api/block/getDocsInfo request handlers. While the product is designed to enforce publish-mode restrictions, the backend fails to filter out metadata related to blocked or restricted resources when fulfilling aggregate reference queries.\nWhen a request is made for a published document, the application retrieves related backlink metadata to populate the UI. The vulnerability manifests because the API logic fetches these backlinks from the database and returns them to the requester without verifying whether the referenced blocks belong to documents that are currently password-protected or restricted from public viewing.\nThe attack flow follows these steps: 1) The attacker identifies a publicly accessible (published) document ID within the target SiYuan instance. 2) The attacker constructs a POST request targeting the /api/block/getDocInfo or /api/block/getDocsInfo endpoints, passing the target document ID as a parameter. 3) The server processes the request and executes a database query to gather references. 4) The server erroneously includes metadata (refIDs and refCount) for all referenced blocks, including those contained within documents that have 'publish-disabled' status or require a password. 5) The server sends a JSON response containing these sensitive identifiers back to the client. 6) The attacker parses the response to identify the existence and relationships of private documents.\nThe exploitation allows an attacker to perform reconnaissance on the knowledge graph of the SiYuan instance. By observing the returned refIDs and refCounts, an attacker can infer the structure of private notes. Since block IDs are often deterministic or sequential within the local storage, this metadata disclosure serves as an effective oracle for confirming the existence of sensitive information, even without direct access to the document content. The exposure of refCount provides further insight into the popularity or interconnectedness of hidden notes, which can be leveraged to prioritize further manual or automated exploitation efforts. This flaw bypasses the logical isolation intended by the password protection feature, effectively nullifying the confidentiality boundary for document references."
}