SiYuan Package Information Disclosure: Early Warning
- Severity
- HIGH
- Affected component
- siyuan (go)
- Patched version
- Not yet available
An early warning has been issued for a potential information disclosure issue in the SiYuan package. Version v3.7.4-alpha.1 is reportedly affected.
What happened
The SiYuan package, specifically version v3.7.4-alpha.1, appears to expose the complete view structure of a database to anonymous readers. This exposure occurs via the /api/av/getAttributeViewFieldViews endpoint, which returns sensitive information including every view's name, icon, layout type, and per-field visibility flags. This issue is under investigation and has not been exploited in the wild as of the latest reports.
Users of the SiYuan package should assess their exposure by checking if they are using the affected version, v3.7.4-alpha.1. It is crucial to monitor the official sources for updates on this issue, as no official fix has been published yet.
What to do about it
- Check your SiYuan package version to see if it is v3.7.4-alpha.1.
- If you are using the affected version, monitor the official SiYuan sources for updates on this issue.
- Consider limiting access to the /api/av/getAttributeViewFieldViews endpoint as a temporary measure until a fix is available.
- Review your database view structures for any sensitive information that may be exposed.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using SiYuan package version v3.7.4-alpha.1.
What should I do right now?
Check your SiYuan package version and monitor the official sources for updates. Consider limiting access to the affected endpoint as a temporary measure.
Has an official fix been released?
No official fix has been published yet. Continue to monitor the sources for updates.