Oct 1, 2026·6 min read·5 visits
Missing authorization checks on the `/api/attr/getBookmarkLabels` endpoint in SiYuan Note allow unauthenticated or unprivileged users to query and retrieve all bookmark labels across the entire workspace, exposing confidential project names, structures, and metadata.
An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the `/api/attr/getBookmarkLabels` API endpoint.
The self-hosted knowledge management platform SiYuan Note exposes a critical information disclosure vector via its internal API endpoint structure. The vulnerability, cataloged as CVE-2026-73609, stems from a complete omission of authorization controls on metadata-retrieval routes. Under normal operations, the application segregates data across distinct notebooks, document paths, and access control tiers.
This flaw resides in the /api/attr/getBookmarkLabels endpoint, which allows unprivileged entities to query system-wide bookmark information. The attack surface is accessible over the default port 6808 when publish-mode or external access features are enabled. Exploitation requires zero privileges and bypasses the defined access controls.
An attacker can systematically query this endpoint to compile a map of internal bookmark tags, exposing administrative structures and private project workflows. The underlying bug falls under CWE-862 (Missing Authorization) and represents a failure in implementing consistent backend authorization scopes. This analysis breaks down the technical mechanism, code paths, and appropriate remediation procedures.
The root cause of CVE-2026-73609 lies within the routing registration and query execution logic of the SiYuan Go-based kernel. In Go-based web frameworks like Gin, endpoint authorization is typically enforced using middleware chains. While administrative endpoints in SiYuan utilize helper functions to validate administrative roles, the /api/attr/getBookmarkLabels route relies solely on the model.CheckAuth middleware, which only checks for basic token presence or is skipped entirely under anonymous publishing configurations.
Once the request reaches the handler, the execution flow triggers model.BookmarkLabels() within the kernel. This function queries the SQLite database via sql.QueryBookmarkLabels(), executing a raw SQL select statement targeting blocks containing Inline Attribute Lists with the substring bookmark. The query pulls every match globally without limiting records to the user's specific context.
The database layer does not check if the current session possesses read permissions for the document containing the retrieved block. It performs no notebook-level filtering, path-level restrictions, or publish-access filtering on the retrieved database blocks. Because of this complete lack of contextual security boundaries, the endpoint returns a unified list of every bookmark label to any caller, regardless of their actual read access limits.
Analysis of the vulnerable routing structure in kernel/api/router.go reveals that the endpoint was registered with minimal authorization validation. Contrast this with the robust security checks used in other sensitive data paths. For instance, the registration flow did not include role checks like those found on administrative configurations.
// Vulnerable route registration
ginServer.Handle("POST", "/api/attr/getBookmarkLabels", model.CheckAuth, getBookmarkLabels)The corresponding backend database query in kernel/sql/block_query.go operates on the database blocks globally, retrieving all attributes without filtering by publishing rights or document path. This execution pattern results in a complete leak of database records.
// Vulnerable query function returning global results
func QueryBookmarkLabels() ([]string, error) {
// SELECT * FROM blocks WHERE ial LIKE '%bookmark=%'
// This retrieves all blocks containing bookmarks globally
}The patch in commit 251596fc0de2f9528c00c224252fd073a99973f4 remedies this issue by introducing validation logic directly into the retrieval path. Similar to the secure getBookmark implementation, the updated code applies FilterBlocksByPublishAccess to the list of blocks. This ensures that any bookmark label that does not associate with at least one block visible to the client is discarded prior to sending the HTTP response.
An attacker can exploit this vulnerability using basic network utilities such as curl or python scripting tools. The attack relies entirely on the default behavior of the target endpoint when publishing features are active. Because no specific parameters are required by /api/attr/getBookmarkLabels, an empty JSON payload is sufficient to execute the query.
POST /api/attr/getBookmarkLabels HTTP/1.1
Host: target-instance:6808
Content-Type: application/json
Content-Length: 2
{}Upon receiving this request, the vulnerable endpoint queries the backend database and returns a complete array of all bookmark labels within the system. The response returns an HTTP 200 OK status code along with the serialized JSON array.
{
"code": 0,
"msg": "",
"data": [
"Internal-Finances-2026",
"Password-Vault-Reference",
"Secret-Project-Alpha"
]
}This response allows the attacker to gather information about internal names, projects, and directories. This exposure facilitates target profiling, providing data that can be used in subsequent target selection or social engineering campaigns.
The impact of CVE-2026-73609 centers on a breach of confidentiality. In environments where SiYuan Note is deployed to host both public documentation and private notes, the exposure of bookmark labels leaks internal metadata. This metadata contains sensitive information such as financial projects, client identifiers, or credential locations.
The Common Vulnerability Scoring System (CVSS) v3.1 rating is 5.8 (Medium), with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. The scope metric is set to changed (S:C) because information leaks from a privileged database boundary to an unprivileged public interface. Under the CVSS v4.0 standard, the severity is evaluated at 6.9.
While there is no direct impact on system integrity or availability, the information gathered from bookmark labels provides an attacker with a roadmap of the workspace. This reduces the difficulty of subsequent attacks by identifying the location of high-value documents within the application database.
The primary remediation path is upgrading the SiYuan Note application to version v3.7.4 or newer. This update patches the endpoint by applying access control checks to filtered block queries. If upgrading is not immediately possible, administrators should implement temporary workarounds to restrict network access to the API.
Administrators can restrict access by binding the service interface strictly to 127.0.0.1 or utilizing a reverse proxy like Nginx or Cloudflare Access to enforce authentication. Blocking the path /api/attr/getBookmarkLabels at the reverse proxy level mitigates the risk without impacting core note-taking capabilities.
Regularly reviewing publishing settings and auditing exposed API paths ensures that private workspace boundaries remain secure. Security teams should deploy host-based detection rules to monitor for unusual access patterns targeting metadata-heavy endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
SiYuan siyuan-note | < v3.7.4 | v3.7.4 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-862 |
| Attack Vector | Network |
| CVSS v3.1 | 5.8 |
| CVSS v4.0 | 6.9 |
| EPSS Score | 0.00325 (0.33%) |
| Exploit Status | Conceptual Proof of Concept |
The platform does not perform an authorization check on an actor when they attempt to access a resource or perform an action.
An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.
An authorization bypass and information leakage vulnerability exists in the SiYuan database module. Unauthenticated users can query the getAttributeViewSearchTarget API endpoint using target block identifiers to extract private content.
CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.
An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.
An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.
A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).