CVSS
5.8
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 14, 2026
Exploitability
No EPSS data available
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).