Junglewise Threat Intelligence

CVE-2026-59853: SiYuan missing authorization in getCriteria endpoint

CVE-2026-59853 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Technologies: SiYuan Note SiYuan, SiYuan. Vendors: SiYuan Note, SiYuan.

Executive brief

SiYuan is an open-source personal knowledge management system used for organizing notes and documents. A security flaw in the system's search criteria endpoint allows users with limited 'Reader' access to view sensitive information that should be private. This includes the titles, file paths, and specific search keywords of unpublished documents, potentially exposing confidential business or personal data to unauthorized individuals.

Technical details

A missing authorization check (CWE-862) exists in the /api/storage/getCriteria endpoint of SiYuan. While sibling endpoints implement 'publish-access' filtering to restrict data based on user roles, this specific endpoint returns the full contents of criteria.json to any user with a 'Reader' role. An attacker with low privileges (such as a visitor to a published notebook) can send a POST request to this endpoint to exfiltrate metadata from private, unpublished documents, including human-readable paths (HPath), internal IDs, and search/replace keywords. The vulnerability is rooted in the kernel/api/storage.go component and was addressed in version 3.7.1 by implementing proper role-based access controls.

Affected products

  • siyuan-note SiYuan < 3.7.1

Timeline

  • 2026-07-02: advisory: GitHub Security Advisory GHSA-px3c-cf92-9g83 published
  • 2026-07-04: patched: Version 3.7.1 released
  • 2026-07-09: disclosed: CVE-2026-59853 published to NVD

References

Related threats