Junglewise Threat Intelligence

SiYuan getAttributeViewSearchTarget information disclosure to anonymous readers

Severity: high · CVSS 8.6 · Published 2026-10-01

Technologies: SiYuan, github.com/siyuan-note/siyuan/kernel (Go). Vendors: SiYuan, Go.

Executive brief

SiYuan is a note-taking application that supports publishing pages in read-only mode. The getAttributeViewSearchTarget API endpoint fails to enforce access controls, allowing anonymous readers to retrieve database row content that should be hidden from them, including rows in documents that are password-protected or encrypted. An attacker can extract this restricted data by querying the endpoint with database identifiers from published pages they can already view.

Technical details

The getAttributeViewSearchTarget endpoint at /api/av/getAttributeViewSearchTarget in the development branch is registered with only CheckAuth middleware and performs no authorization checks on the requested database. It lacks the CheckReadonly middleware and access filters (CheckAttributeViewBlockAccessableByPublishAccess, FilterAttributeViewByPublishAccess) that parallel endpoints apply. An unauthenticated or read-only user can query arbitrary databases and rows, including those in encrypted notebooks and restricted blocks, by deriving database identifiers from published page markup.

Affected products

  • SiYuan SiYuan development branch after commit 9b8e8956f (2026-07-27); not present in v3.7.3 or stable releases

Timeline

  • 2026-10-01: disclosed

Related threats