Sceawere

Vulnerability Detail

CVE-2026-73606UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
9h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-08-13T12:17:25.043Z",
  "pubdate": "2026-08-13T12:17:25.043Z",
  "executiveSummary": "SiYuan versions prior to v3.7.4 suffer from an information disclosure vulnerability residing within the /api/block/getRefIDs endpoint. The vulnerability stems from an authorization bypass condition where the application fails to enforce password protection validation tiers on sensitive documents. Consequently, unauthenticated remote attackers can query the vulnerable endpoint to ascertain whether password-protected documents contain references to specific internal data structures. By exploiting this flaw, unauthorized principals can harvest internal block identifiers without possessing the requisite document-level decryption passwords. This compromise undermines the confidentiality guarantees of encrypted workspace partitions, exposing structural metadata and reference topologies of confidential notes to external observers. The risk implications include unauthorized enumeration of protected workspace content and potential reconnaissance mapping prior to advanced targeting. Exploitation requires network access to the target SiYuan instance HTTP API but demands zero prior authentication credentials or valid document passwords.",
  "technicalDetails": "The vulnerability is localized to the /api/block/getRefIDs endpoint of the SiYuan application backend. The root cause of the flaw is inadequate access control enforcement and missing authorization checks regarding password-protected document tiers during reference identifier resolution. In a secure implementation, endpoints processing requests related to encrypted or password-restricted documents must validate the caller's authorization state and verify whether the corresponding document session is authenticated or decrypted. However, in vulnerable versions prior to v3.7.4, the /api/block/getRefIDs handler processes queries without validating if the referenced blocks reside within a password-protected boundary.\nThe attack flow proceeds as follows: 1) An unauthenticated adversary targets the HTTP API of an exposed SiYuan instance over the network. 2) The attacker issues a crafted request directed at the /api/block/getRefIDs endpoint, specifying target block or document parameters. 3) The backend application executes the query logic to retrieve reference identifiers associated with the requested blocks. 4) Due to the absence of password-tier validation, the application bypasses access restrictions that should normally shield encrypted documents. 5) The server responds with the requested block identifiers and reference mapping data, disclosing structural relationships of confidential notes without prompting the client for a document password.\nThe affected component is the API routing and controller logic handling block reference resolution in SiYuan versions before v3.7.4. The vulnerability is exploitable remotely over the network without requiring any authentication privileges or prior knowledge of the document-level password. Successful exploitation yields post-exploitation reconnaissance capabilities, allowing malicious actors to map out internal document structures, discover hidden relationships between sensitive notes, and gather valid block identifiers for further enumeration attacks."
}
CVE-2026-73606: SiYuan Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.8) - Sceawere