Executive brief
SiYuan is a personal knowledge management application with note-taking and publishing capabilities. An authenticated administrator can bypass a security guard designed to block access to sensitive files (including plaintext publish passwords and template files) by accessing historical snapshots through the /history and /repo/diff endpoints, potentially exposing credentials and configuration data that should be protected.
Technical details
The vulnerability is a missing authorization check (CWE-862/CWE-200) in two HTTP endpoints: /history/*path and /repo/diff/*path in kernel/server/serve.go. While these endpoints require admin authentication and were meant to be protected by the IsForbiddenAbsPath guard (introduced in a prior advisory GHSA-c8r8-95hg-mp34), they construct file paths independently without calling this guard. An authenticated admin attacker can retrieve historical or diff-view copies of sensitive files such as data/.siyuan/publishAccess.json (containing plaintext publish-mode passwords) and files under data/templates/ that exist in the repository history or diff-checkout directory. The guard successfully protects live file access endpoints but fails to cover these archive/history endpoints. The vulnerability requires admin-level authentication and network access to the affected SiYuan instance (typically port 6806). Patched in version 3.8.1.
Affected products
- SiYuan SiYuan before 3.8.1
Timeline
- 2026-08-30: disclosed
- 2026-08-30: patched: patched in v3.8.1