GHSA-8x84-r2ff-h8pq: SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
Summary
SiYuan's encrypted-notebook system leaks critical password-cracking material to anonymous readers through two API endpoints. Specifically, the `/api/system/getConf` endpoint exposes the Argon2id salt (input material for a key-derivation function that stretches passwords into encryption keys), cost parameters, and a password verifier that lets attackers test guesses offline on their own GPU without server rate limits, while `/api/notebook/getNotebookConf` exposes the wrapped per-notebook encryption key. Together, these disclosures reduce security to the master password's resistance to offline brute-force cracking.
Vulnerability Details
EPSS: 0.2%
Yes
September 3, 2026
Classification
Affected Packages
Original source: https://github.com/advisories/GHSA-8x84-r2ff-h8pq
First tracked: September 3, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%