Executive brief
SiYuan is a personal knowledge management system that allows users to organize and publish documents. A security flaw in its publishing service allows unauthorized visitors to view content from documents that are supposed to be password-protected. If a user has bookmarked a section within a protected document, an attacker can bypass the password requirement to read that specific content, potentially exposing sensitive private information.
Technical details
An authorization bypass exists in the `/api/bookmark/getBookmark` endpoint of SiYuan's publish service. The vulnerability is caused by the `getBookmark` function passing a `nil` context to `FilterBlocksByPublishAccess`. The filtering logic incorrectly interprets a `nil` context as an authorized state, skipping the `CheckPublishAuthCookie` routine that validates document passwords. Consequently, any unauthenticated user can retrieve bookmarked blocks from documents marked as 'Protected' by sending a crafted POST request to the bookmark API. This issue is resolved in version 3.6.2.
Affected products
- siyuan-note SiYuan < 3.6.2
Timeline
- 2026-03-18: other: Issue reported to vendor
- 2026-03-28: advisory: GitHub Security Advisory published
- 2026-03-31: patched: Version 3.6.2 released
- 2026-03-31: disclosed: CVE published