CVE-2026-45148 PUBLISHED

SiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata

Assigner: GitHub_M
Reserved: 08.05.2026 Published: 14.05.2026 Updated: 14.05.2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This vulnerability is fixed in 3.7.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor siyuan-note
Product siyuan
Versions
  • Version < 3.7.0 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE