Executive brief
SiYuan is a note-taking and knowledge management application. The `/api/system/getConf` endpoint exposes the administrator's live workspace layout—including open document titles, search terms, asset paths, and identifiers—to any unauthenticated reader when publish mode is enabled. An attacker can repeatedly poll this endpoint to monitor what the administrator is working on in real time.
Technical details
The vulnerability exists in the `FilterConfByPublishIgnore` function which attempts to filter sensitive content from `UILayout` before serving it to readers, but fails due to four defects: (1) password-protected documents are not checked for access tier, (2) unresolvable document references fail open instead of closed, (3) non-editor tab types (Asset, Search, Outline, Custom) bypass filtering entirely, and (4) dock panels are not filtered. An unauthenticated POST to `/api/system/getConf` with no arguments exploits all four defects simultaneously to disclose administrator workspace state.
Affected products
- SiYuan SiYuan 3.7.4-alpha.1 and likely earlier versions
Timeline
- 2026-10-01: disclosed: Vulnerability published as GHSA-hgfg-j9pg-43xw