Kernel: Duplicate Advisory: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
SiYuan versions before v3.7.4 have an information disclosure vulnerability in the /api/block/getRefIDs endpoint. This endpoint does not properly enforce password protection tiers, allowing unauthenticated users to discover references to specific blocks within password-protected documents without needing the document password. The advisory is a duplicate and has been withdrawn in favor of GHSA-vg99-7gj7-2fr5.
AI Analysis
Technical Summary
The vulnerability exists in SiYuan note-taking software versions prior to v3.7.4. The /api/block/getRefIDs endpoint fails to verify the password tier of documents when returning references to blocks. As a result, unauthenticated users can obtain block identifiers referenced by password-protected documents, leading to partial information disclosure. The advisory is a duplicate of GHSA-vg99-7gj7-2fr5 and has been withdrawn accordingly.
Potential Impact
An attacker without authentication can determine that password-protected documents reference certain blocks and obtain those block identifiers without needing to enter the document password. This leads to partial information disclosure but does not allow modification or denial of service.
Mitigation Recommendations
The vulnerability is fixed in SiYuan version 3.7.4. Users should upgrade to version 3.7.4 or later to remediate this issue. Since this advisory is a duplicate and withdrawn, refer to GHSA-vg99-7gj7-2fr5 for official patch and remediation details.
Kernel: Duplicate Advisory: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Description
SiYuan versions before v3.7.4 have an information disclosure vulnerability in the /api/block/getRefIDs endpoint. This endpoint does not properly enforce password protection tiers, allowing unauthenticated users to discover references to specific blocks within password-protected documents without needing the document password. The advisory is a duplicate and has been withdrawn in favor of GHSA-vg99-7gj7-2fr5.
CVSS v3.1
Score 5.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in SiYuan note-taking software versions prior to v3.7.4. The /api/block/getRefIDs endpoint fails to verify the password tier of documents when returning references to blocks. As a result, unauthenticated users can obtain block identifiers referenced by password-protected documents, leading to partial information disclosure. The advisory is a duplicate of GHSA-vg99-7gj7-2fr5 and has been withdrawn accordingly.
Potential Impact
An attacker without authentication can determine that password-protected documents reference certain blocks and obtain those block identifiers without needing to enter the document password. This leads to partial information disclosure but does not allow modification or denial of service.
Mitigation Recommendations
The vulnerability is fixed in SiYuan version 3.7.4. Users should upgrade to version 3.7.4 or later to remediate this issue. Since this advisory is a duplicate and withdrawn, refer to GHSA-vg99-7gj7-2fr5 for official patch and remediation details.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gq43-vcrh-6jw8
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6abeb3f6a43b0b3b89ed4861
Added to database: 10/01/2026, 19:26:46 UTC
Last enriched: 10/01/2026, 19:36:39 UTC
Last updated: 10/01/2026, 19:36:39 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.