CVE-2026-103763: SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo
SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any read-only publish reader can query publish-visible notebooks. If no reader password is configured, anonymous visitors can do so.
What information can be exposed?
The endpoint can reveal metadata for documents excluded from publishing, including document counts, sizes, and modification timestamps. The available data describes metadata disclosure only, not disclosure of the hidden document contents.
Which deployments are affected?
SiYuan versions before v3.8.5 are affected where publish-visible notebooks are accessible to read-only readers. Exposure is greatest when published content has no reader password because anonymous visitors can make the queries.
How can I tell whether my instance is exposed?
Check whether the SiYuan version is earlier than v3.8.5 and whether publish-visible notebooks contain documents excluded from publishing. Also determine whether reader access is password-protected; without a password, anonymous users may be able to query the affected endpoint.