思源笔记(SiYuan)在 3.8.5 版本之前存在一个信息泄露漏洞,该漏洞允许发布模式下的读者通过查询已发布的文档,从受密码保护且未启用发布功能的文档中获取反向链接块(backlink block)的 ID 和引用计数。攻击者可以向 或 接口发送 POST 请求,传入已发布文档的 ID,从而获取隐藏的引用块所对应的 refIDs 和 refCount,从而绕过发布机制所设定的保密边界。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.5 |
affected |
3.8.5 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet