Sceawere

Vulnerability Detail

CVE-2026-73609UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
9h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-08-13T12:17:25.463Z",
  "pubdate": "2026-08-13T12:17:25.463Z",
  "executiveSummary": "SiYuan versions prior to v3.7.4 suffer from an information disclosure vulnerability residing within the getBookmarkLabels endpoint. This security flaw enables unauthorized users, specifically anonymous readers and publish-mode readers, to retrieve all bookmark labels present within the workspace without enforcing proper publish-access filtering mechanisms. The primary impact of this vulnerability is the unintended exposure of sensitive organizational metadata and subject matter derived from documents that should otherwise remain inaccessible to these permission tiers. The risk implications involve potential reconnaissance and intelligence gathering by unprivileged entities, mapping out internal taxonomies and document categories. The attacker capabilities are limited to reading the complete bookmark vocabulary of the workspace via the exposed endpoint. Exploitation requirements include network access to the target SiYuan instance and the ability to interact with the vulnerable getBookmarkLabels endpoint under anonymous or publish-mode reader privileges, requiring no prior authentication or administrative privileges.",
  "technicalDetails": "The vulnerability stems from inadequate access control enforcement and missing authorization checks within the getBookmarkLabels endpoint of SiYuan prior to version v3.7.4. The vulnerable component fails to validate whether the requesting entity possesses the necessary publish-access permissions for the documents associated with the requested bookmark labels. As a result, the backend application logic processes requests from unauthenticated or restricted users and returns the aggregate set of bookmark labels globally across the entire workspace.\nThe attack flow proceeds as follows: an attacker with network exposure to the SiYuan application, operating under an anonymous session or restricted publish-mode reader context, issues an HTTP request directly to the getBookmarkLabels endpoint. Because the application logic lacks proper context-aware filtering against document-level visibility permissions, the server queries the underlying data store for all bookmark labels without restricting the result set based on the caller's privilege level. The server serializes the complete bookmark vocabulary into the response payload and transmits it back to the client.\nThe post-exploitation impact includes the systematic enumeration of workspace topics, project names, and categorization structures. Although the vulnerability does not directly grant arbitrary read access to the full document contents, the leakage of bookmark labels provides critical structural intelligence and contextual insights into confidential materials. This metadata exposure facilitates further targeted attacks or unauthorized information mapping against the affected workspace."
}
CVE-2026-73609: SiYuan Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.8) - Sceawere