SiYuan Package Exposes Database View Structure to Anonymous Readers
- Severity
- HIGH
- Affected component
- siyuan (go)
- Affected versions
- <= 0.0.0-20260313024916-fd6526133bb3
- Patched version
- Not yet available
An early warning has been issued for the SiYuan package, which reportedly exposes database view structure to anonymous readers through the /api/av/getAttributeViewFieldViews endpoint. This includes view names, icons, layout types, and per-field visibility flags.
What happened
The SiYuan package, specifically versions up to and including 0.0.0-20260313024916-fd6526133bb3, appears to expose sensitive database view structure information to anonymous readers. This exposure occurs via the /api/av/getAttributeViewFieldViews endpoint, which returns view names, icons, layout types, and per-field visibility flags without authentication.
This issue was first flagged on 2026-09-08T17:53:44+00:00 and is currently under investigation. The severity of this issue is classified as high due to the potential for unauthorized access to sensitive database configurations.
What to do about it
- Upgrade to a version of SiYuan that includes a fix for this issue, if available.
- Apply a patch if one has been released to address this vulnerability.
- Monitor the primary sources for updates on this issue, as no official fix has been published yet.
How 0Day would have caught this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using SiYuan package version 0.0.0-20260313024916-fd6526133bb3 or earlier.
What should I do right now?
Upgrade to a patched version of SiYuan if available, or apply a patch if one has been released. Monitor the primary sources for updates.
Has this issue been exploited in the wild?
There is no confirmed report of this issue being exploited in the wild at this time.