Junglewise Threat Intelligence

CVE-2026-34453: SiYuan incorrect authorization in bookmark API publish service

CVE-2026-34453 · Severity: high · CVSS 7.5 · Published 2026-03-31

Technologies: SiYuan, github.com/siyuan-note/siyuan/kernel (Go), SiYuan Note SiYuan. Vendors: SiYuan, Go, SiYuan Note.

Executive brief

SiYuan is a personal knowledge management system that allows users to organize and publish documents. A security flaw in its publishing service allows unauthorized visitors to view content from documents that are supposed to be password-protected. If a user has bookmarked a section within a protected document, an attacker can bypass the password requirement to read that specific content, potentially exposing sensitive private information.

Technical details

An authorization bypass exists in the `/api/bookmark/getBookmark` endpoint of SiYuan's publish service. The vulnerability is caused by the `getBookmark` function passing a `nil` context to `FilterBlocksByPublishAccess`. The filtering logic incorrectly interprets a `nil` context as an authorized state, skipping the `CheckPublishAuthCookie` routine that validates document passwords. Consequently, any unauthenticated user can retrieve bookmarked blocks from documents marked as 'Protected' by sending a crafted POST request to the bookmark API. This issue is resolved in version 3.6.2.

Affected products

  • siyuan-note SiYuan < 3.6.2

Timeline

  • 2026-03-18: other: Issue reported to vendor
  • 2026-03-28: advisory: GitHub Security Advisory published
  • 2026-03-31: patched: Version 3.6.2 released
  • 2026-03-31: disclosed: CVE published

References

Related threats