Executive brief
SiYuan is a personal knowledge management system. A security flaw in its publishing service allows unauthorized visitors to see metadata from private notebooks that were intended to be hidden. This includes the names of private files, tags, and templates, which could expose sensitive project names or personal information.
Technical details
A broken access control vulnerability exists in the SiYuan kernel's search API endpoints (/api/search/searchAsset, /api/search/searchTag, /api/search/searchWidget, and /api/search/searchTemplate). While other similar endpoints implement 'FilterBlocksByPublishAccess' to respect notebook privacy settings, these four handlers lack the necessary logic to branch on 'model.IsReadOnlyRoleContext'. Consequently, an attacker with a valid 'RoleReader' JWT (typically assigned to anonymous visitors of the publish service) can query and receive global metadata including tag strings, asset filenames, and template names from notebooks marked as private or publish-ignored. This has been patched in version 0.0.0-20260512140701-d7b77d945e0d.
Affected products
- siyuan-note SiYuan < 0.0.0-20260512140701-d7b77d945e0d
Timeline
- 2026-05-08: disclosed: Advisory published to repository
- 2026-05-12: patched: First patched version released
- 2026-05-13: advisory: GitHub Advisory published