Oct 1, 2026·7 min read·2 visits
A Broken Object Level Authorization (BOLA) vulnerability in SiYuan prior to v3.7.4 allows authenticated users to extract document outlines and structural metadata of unauthorized notes via the `/api/storage/getOutlineStorage` API endpoint.
An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.
SiYuan is a local-first, privacy-focused knowledge management platform written primarily in Go. When deployed in server mode, the platform utilizes a Go-based kernel to handle the local database, file storage, and HTTP API endpoints. This architecture exposes a variety of API endpoints to clients and web-based interfaces to manage notebooks, assets, and document hierarchies.
One specific API endpoint registered by the kernel is /api/storage/getOutlineStorage. This endpoint is designed to manage the outline metadata and folding state of individual notes. By tracking which headings are folded or expanded, the platform maintains a consistent UI state across different sessions and client devices.
While the application utilizes session-based authentication middleware to restrict endpoint access to registered users, it failed to implement granular authorization checks on the underlying document objects. This configuration creates an attack surface where basic authentication acts as a blanket permit, allowing any authenticated identity to query resource states regardless of their explicit permission tier.
This flaw is classified as a Broken Object Level Authorization (BOLA) vulnerability, tracked under CWE-862 (Missing Authorization). It has a CVSS v3.1 score of 5.8, indicating a moderate confidentiality risk that particularly impacts multi-user collaborative environments or instances exposed to public networks with guest registration enabled.
The vulnerability resides in the logical separation between authentication and authorization boundaries within the SiYuan Go kernel. When an HTTP request is made to /api/storage/getOutlineStorage, the routing middleware successfully intercepts the request to validate session cookies or bearer tokens. If the token is valid, control is handed over to the endpoint's controller function.
The controller function parses the incoming JSON request payload to extract the id field, which represents the targeted document's unique identifier. The backend then proceeds to query the storage layer or database to locate the corresponding outline structure. However, the system fails to check if the authenticated user has read permissions for the specific notebook or parent workspace hosting that document ID.
In a secure implementation, the controller must perform an explicit lookup against the access control list (ACL) or database permissions before retrieving the data. Because this lookup step was missing, the kernel directly retrieves the outline document from the storage path and serializes it to the HTTP response writer. This direct path allows the request to bypass the document-level read restrictions completely.
To illustrate the technical mechanism of the vulnerability, we can analyze the conceptual Go handler architecture. In the vulnerable version, the router registers the route with basic authentication middleware but neglects path authorization checks:
// Vulnerable route registration and handler example
router.POST("/api/storage/getOutlineStorage", middleware.CheckAuth, func(c *gin.Context) {
var req struct {
ID string `json:"id"`
}
if err := c.ShouldBindJSON(&req); err != nil {
c.JSON(400, gin.H{"error": "invalid request"})
return
}
// VULNERABILITY: Directly retrieving the outline without checking if the authenticated
// user has access permissions to the document ID 'req.ID'
outline, err := storage.GetOutline(req.ID)
if err != nil {
c.JSON(404, gin.H{"error": "outline not found"})
return
}
c.JSON(200, outline)
})The patch introduced in version 3.7.4 rectifies this by inserting an explicit permission validation block immediately after binding the request data. This check validates the user's role against the target document ownership or sharing permissions:
// Patched route registration and handler example
router.POST("/api/storage/getOutlineStorage", middleware.CheckAuth, func(c *gin.Context) {
var req struct {
ID string `json:"id"`
}
if err := c.ShouldBindJSON(&req); err != nil {
c.JSON(400, gin.H{"error": "invalid request"})
return
}
// Get user context from session
user, _ := c.Get("user")
// FIX: Verify if the authenticated user has explicit read access to the document
hasAccess := auth.CheckDocAccess(user.ID, req.ID, auth.PermissionRead)
if !hasAccess {
c.JSON(403, gin.H{"error": "forbidden"})
return
}
outline, err := storage.GetOutline(req.ID)
if err != nil {
c.JSON(404, gin.H{"error": "outline not found"})
return
}
c.JSON(200, outline)
})This modification ensures that the kernel performs access validation as a hard gate before querying the file system or database. However, developers must ensure that similar endpoints, such as other /api/storage/* or metadata queries, also implement uniform checks to avoid variant access bypasses.
The exploitation of CVE-2026-73607 requires an attacker to possess valid credentials for the target SiYuan instance. This makes the threat model relevant to multi-user collaborative workspaces, corporate wikis, or instances allowing self-registration of guest accounts. The attack is highly structured and can be automated to scan for specific document configurations.
The flow of the exploitation technique can be visualized as follows:
To perform the extraction, the attacker constructs an HTTP POST request targeting /api/storage/getOutlineStorage and provides the document's UUID. Even if the attacker's account is explicitly restricted from accessing the notebook containing the document, the server responds with a 200 OK containing the structural outline nodes. This data exposes precise heading texts and block hierarchies, allowing attackers to reconstruct document structures and leak sensitive string variables containing credentials or project details.
The impact of this information disclosure is evaluated as moderate, primarily affecting confidentiality. While the endpoint does not return the complete paragraph text blocks of the target note, document outlines and headers in professional or personal environments frequently contain highly sensitive metadata. Headings often document passwords, database configurations, architectural flowcharts, or client information.
In addition to direct metadata leakage, obtaining the heading UUIDs provides the attacker with functional references to block identifiers. These block identifiers can potentially be leveraged in subsequent API queries to reconstruct more extensive document trees if other endpoints suffer from similar authorization validation deficiencies.
The CVSS v4.0 score of 6.9 and v3.1 score of 5.8 reflect that the vulnerability does not require complex attack conditions or user interaction. Its reliance on standard authenticated accounts limits the threat vector primarily to internal threat actors or compromised low-privilege sessions. The EPSS score is currently evaluated at 0.00325, indicating a low immediate probability of automated exploitation in the wild, though targeted attacks remain highly viable.
The primary remediation path is upgrading the SiYuan application kernel to version 3.7.4 or later. For broader stability and complete patch inclusion, administrators are strongly recommended to deploy version 3.8.0 or subsequent releases. Upgrading guarantees that the backend router utilizes resource authorization filters before servicing outline storage requests.
In environments where immediate patching is not operationally feasible, administrators must implement network-level segmentation to mitigate potential exposure. Placing the SiYuan web interface behind a Virtual Private Network (VPN) or a reverse proxy with IP whitelisting limits the attack surface. Furthermore, self-registration should be disabled on multi-user instances to prevent unauthorized actors from establishing valid sessions.
Security teams can monitor application server logs for anomalous patterns of requests hitting the /api/storage/getOutlineStorage endpoint. A high volume of requests for distinct document IDs originating from a single session or IP address is a key indicator of automated document enumeration. Restricting API token generation to verified administrative accounts further reduces the likelihood of successful exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
SiYuan siyuan-note | >= 0, < 3.7.4 | 3.7.4 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-862 (Missing Authorization) |
| Attack Vector | Network (AV:N) |
| CVSS v3.1 / v4.0 | 5.8 (Medium) / 6.9 (Medium) |
| EPSS Score | 0.00325 (Percentile: 23.20%) |
| Impact | Information Disclosure (Confidentiality: Low) |
| Exploit Status | PoC Available / No Active Exploitation |
| KEV Status | Not Listed |
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the `/api/attr/getBookmarkLabels` API endpoint.
An authorization bypass and information leakage vulnerability exists in the SiYuan database module. Unauthenticated users can query the getAttributeViewSearchTarget API endpoint using target block identifiers to extract private content.
CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.
An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.
An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.
A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).