Vulnerability GHSA-hgfg-j9pg-43xw

Medium Risk
MEDIUM RISK
CVSS Score: 5.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 01, 2026 at 02:39 PM UTC
SiYuan discloses an administrator's open documents and search terms to anonymous readers
<0.0.0-20260812083335-251596fc0de2
<0.0.0-20260812083335-251596fc0de2

Summary

SiYuan discloses an administrator's open documents and search terms to anonymous readers

Details

Summary

/api/system/getConf serves Conf.UILayout to publish readers after passing it through FilterConfByPublishIgnore, whose only function is to filter that layout. The layout is written exclusively by setUILayout, which is administrator-gated, so what readers receive is the administrator's own live workspace state, re-saved on every tab open, close and focus change.

The filter that is supposed to protect it, filterLayoutItemByPublishIgnore, has four separate defects. Together they mean a single unauthenticated POST with no arguments returns the titles and identifiers of the administrator's open password-protected documents, the titles of documents in locked or closed notebooks, their recent search terms and the paths those searches were scoped to, and the paths of private assets they have open.

This report concerns FilterConfByPublishIgnore and its layout walker. It is distinct from the previously reported getConf issues, which concern configuration fields surviving HideConfSecret's blocklist. Restructuring the secret-masking path would not affect this, because UILayout is not a secret to be stripped. It is a field intended to be served and filtered.

Details

Route and writer asymmetry. kernel/api/router.go:70 registers POST /api/system/getConf with model.CheckAuth only, so it is reachable by the publish RoleReader token and anonymously when Publish.Auth.Enable is false. The corresponding writer, setUILayout at kernel/api/router.go:67, carries CheckAuth, CheckAdminRole and CheckReadonly. Only an administrator can write this state, and any reader can read it.

The filter exists and is intended to work. HideConfSecret never touches UILayout (zero matches on both refs). Instead the reader branch runs:

if model.IsReadOnlyRoleContext(c) {
    publishIgnore := model.GetInvisiblePublishAccess(publishAccess)
    maskedConf = model.FilterConfByPublishIgnore(publishIgnore, maskedConf)
}

FilterConfByPublishIgnore does exactly one thing, which is filter UILayout. The intent that readers must not see the administrator's private tabs is therefore already established in the code. The four defects below are failures of that filter, not an argument that it should exist.

filterLayoutItemByPublishIgnore is byte-identical at eef105683 and v3.7.4-alpha.1 and has not changed since 3facc37df (#16041).

Timeline

Published
2 hours ago
October 01, 2026 at 02:39 PM UTC
Last Modified
2 hours ago
October 01, 2026 at 03:00 PM UTC