Sceawere
Vulnerability Detail
CVE-2026-73048UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiYuan Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.8
- Creation Date
- 3h ago
- Vendor
- siyuan-note
- Product
- siyuan
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.8",
"pubDate": "2026-08-14T12:16:47.567Z",
"pubdate": "2026-08-14T12:16:47.567Z",
"executiveSummary": "An information disclosure vulnerability exists in SiYuan versions before v3.7.4 within the getRefIDsByFileAnnotationID endpoint.\nThe vulnerability allows unauthorized extraction of block identifiers citing PDF annotations by bypassing publish-access filtering mechanisms.\nAffected systems include SiYuan instances running software versions prior to v3.7.4.\nThe risk implications involve the leakage of citation relationships and structural metadata spanning across forbidden and password-protected document tiers.\nAttackers with the capability to observe annotation identifiers exposed on publicly accessible pages can leverage this endpoint to query restricted documents.\nExploitation requires the ability to interact with the vulnerable API endpoint and supply valid, visible annotation identifiers to infer relationships with restricted content.",
"technicalDetails": "The vulnerability resides in the getRefIDsByFileAnnotationID endpoint of the SiYuan application, specifically affecting versions prior to v3.7.4.\nThe root cause of the flaw is the absence of proper authorization checks and publish-access filtering when processing requests to the vulnerable function.\nNetwork exposure encompasses the application endpoints handling PDF annotation references and block identifier retrievals.\nThe attack flow begins when an attacker identifies PDF annotation identifiers that are inadvertently exposed within publicly accessible pages or documents.\nThe attacker then crafts requests targeting the getRefIDsByFileAnnotationID endpoint, supplying the harvested annotation identifiers as input parameters.\nBecause the vulnerable component fails to enforce security boundaries or verify whether the requesting entity possesses authorization for the associated files, it processes the request without evaluating publish-access restrictions.\nThe backend function returns block identifiers citing the specified PDF annotations, even when those blocks reside within forbidden, private, or password-protected document tiers.\nThis behavior results in unauthorized data leakage, allowing attackers to map citation relationships, deduce document connectivity, and harvest internal identifiers belonging to restricted workspace content."
}