SiYuan below v3.7.4 has authorization flaw rated 8.7
A missing authorization vulnerability (CWE-862) with a CVSS score of 8.7 affects the SiYuan note-taking app before v3.7.4. Seventeen endpoints in kernel/api/block.go lack publish-access and role checks, letting anonymous users read private notes and map workspace structure. The flaw is fixed in v3.7.4.
- CVSS 8.7 (v4.0) and 7.5 (v3.1), network attack vector
- 17 endpoints in kernel/api/block.go lack publish-access checks
- SiYuan versions below 3.7.4 affected, fixed in v3.7.4
- Public PoC available, not listed in KEV catalog
Read next
Security