GHSA-rchc-g58m-88jmMediumCVSS 5.8
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the...
🔗 CVE IDs covered (1)
📋 Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.