GHSA-h4v5-crx2-3cv4: SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
highvulnerability
security
Summary
SiYuan's `/api/system/getConf` API endpoint leaks three sensitive secrets to unauthenticated users: the session-cookie signing key (used to forge login sessions), the OS username embedded in a file path, and encrypted-notebook key material. These three fields are explicitly hidden by a separate configuration-export endpoint, but the blocklist-based masking (which names fields individually rather than using a default-deny approach) missed them, causing them to be returned to anyone who can reach the endpoint.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.2%
Patch Available
Yes
Disclosure Date
September 4, 2026
Classification
Attack SophisticationModerate
Affected Packages
github.com/siyuan-note/siyuan/kernel@< 0.0.0-20260725132049-2d8b98395a91 (fixed: 0.0.0-20260725132049-2d8b98395a91)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-h4v5-crx2-3cv4
First tracked: September 4, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%