Executive brief
SiYuan is a note-taking and knowledge management application that supports password-protected documents. This vulnerability allows unauthenticated readers to discover that password-protected documents contain references to specific blocks without providing the document password, leaking the existence of cross-document relationships and revealing block identifiers.
Technical details
The /api/block/getRefIDs endpoint performs an incomplete authorization check when filtering reference results. Specifically, the FilterRefDefsByPublishIgnore helper function checks only visibility tiers but does not verify the password tier because it does not receive the HTTP request context (gin.Context) needed to validate the publish authentication cookie. An unauthenticated or role-based reader can invoke this endpoint in publish mode without a password to enumerate references from password-protected documents, receiving block identifiers and relationship metadata without passing authentication. The vulnerability is Authorization Bypass (CWE-639), stemming from missing password validation in a filtering function that has a correct counterpart elsewhere in the same codebase. The response contains only identifiers and relationship existence—no document content—limiting exposure to confidentiality. A patch was released in v3.7.4 that threads the request context into the filtering functions and applies the complete access check.
Affected products
- SiYuan SiYuan before v3.7.4
Timeline
- 2026-07-29: disclosed
- 2026-08-13: advisory
- 2026: patched: v3.7.4 released