CVE-2026-103763
Deferred Deferred - Pending Action

SiYuan Information Disclosure via getNotebookInfo Endpoint

Vulnerability report for CVE-2026-103763, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan before v3.8.5 has an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint. This allows read-only publish readers, and anonymous visitors if no reader password is set, to access metadata of documents excluded from publishing. Attackers can query publish-visible notebooks to get the count, size, and modification timestamps of hidden documents.

Detection Guidance

To detect this vulnerability, monitor HTTP POST requests to the /api/notebook/getNotebookInfo endpoint. Check if responses include metadata like document count, size, or timestamps for documents that should be hidden. Use network traffic analysis tools like Wireshark or tcpdump to inspect requests to this endpoint.

Impact Analysis

This vulnerability exposes sensitive metadata about documents you intended to keep private. Attackers can learn the existence, number, size, and recent modification times of hidden documents in your published notebooks. This does not reveal document titles, paths, or contents but still compromises confidentiality of your note organization.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by exposing metadata about documents containing sensitive information. GDPR requires protecting personal data, and HIPAA requires safeguarding protected health information. Metadata exposure may violate these regulations if it reveals information about restricted documents.

Mitigation Strategies

Upgrade SiYuan to version 3.8.5 or later. If upgrading is not possible, set a reader password for the publish service and avoid publishing notebooks with mixed published and excluded documents. Restrict access to the /api/notebook/getNotebookInfo endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103763. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart