CVE-2026-33669: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33669 is an arbitrary document reading vulnerability in SiYuan, a personal knowledge management system developed by b3log. Prior to version 3.6.2, unauthenticated attackers could enumerate document IDs via the /api/file/readDir interface and then retrieve the full content of all documents — including encrypted or access-restricted ones — via the /api/block/getChildBlocks interface. The vulnerability was disclosed on March 23, 2026, and patched in version 3.6.2. It carries a CVSS v3.1 base score of 9.8 (Critical) per the GitHub Security Advisory, though Feedly's NVD-sourced data notes a score of 7.5 (High) focused solely on confidentiality impact (GitHub Advisory, GHSA Database).

Technical details

The vulnerability stems from missing access controls on two API endpoints within SiYuan's publishing service. An attacker first calls the /api/file/readDir endpoint to enumerate document IDs without authentication, then submits those IDs to the /api/block/getChildBlocks endpoint via HTTP POST to retrieve full document block content — including content that should be encrypted or restricted. The flaw is classified as CWE-125 (Out-of-bounds Read), though the practical exploitation behavior is more accurately described as an improper authorization / missing authentication for critical function issue. A public proof-of-concept Python script is available that automates both steps (GitHub Advisory, GHSA Database).

Impact

Successful exploitation allows an unauthenticated remote attacker to read the full content of all documents stored within a SiYuan publishing service instance, including documents that are encrypted or otherwise access-restricted. The primary impact is a complete loss of confidentiality for all knowledge base content, which may include sensitive personal notes, credentials, or proprietary information. There is no direct integrity or availability impact, though exposure of sensitive document content could facilitate further targeted attacks (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept Python exploit script is available within the GitHub Security Advisory itself, demonstrating automated document enumeration and content extraction with no authentication required (GitHub Advisory). The EPSS score is approximately 0.023% (0.000430 per Feedly), placing it in the 7th percentile for near-term exploitation likelihood. There is currently no evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The attack requires no privileges, no user interaction, and is exploitable over the network with low complexity (GHSA Database).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or locally accessible SiYuan instances running versions prior to 3.6.2, typically listening on port 6806 (default). Use tools like Shodan or Censys to locate exposed instances.
  2. Enumerate document IDs: Send an unauthenticated HTTP GET or POST request to the /api/file/readDir endpoint to list directory contents and retrieve document IDs (typically alphanumeric block IDs used by SiYuan's internal data model).
  3. Extract document content: For each discovered document ID, send an unauthenticated HTTP POST request to /api/block/getChildBlocks with the payload {"id": "<doc_id>"} and Content-Type: application/json.
  4. Parse and exfiltrate: Parse the JSON response to extract the markdown or content fields from each returned block object, reconstructing the full document content. Optionally save results to a local JSON file for offline analysis.
  5. Target sensitive documents: Repeat for all enumerated document IDs to systematically exfiltrate the entire knowledge base, including encrypted or restricted documents (GitHub Advisory).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP POST requests to /api/block/getChildBlocks from external or unexpected IP addresses; repeated unauthenticated requests to /api/file/readDir for directory enumeration; high-volume sequential API calls suggesting automated document harvesting.
  • Logs: SiYuan access logs showing multiple requests to /api/file/readDir and /api/block/getChildBlocks from the same source IP without authentication tokens; requests with Content-Type: application/json bodies containing only an id field targeting the block API.
  • Process/Behavioral: Sudden spike in API request volume to the SiYuan service process; outbound data transfers from the SiYuan host following enumeration activity (GitHub Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.6.2 or later, which patches the unauthorized access to the affected API endpoints (GitHub Advisory). As an interim workaround, restrict network access to the SiYuan instance to trusted users or networks only (e.g., via firewall rules or binding the service to localhost). Additionally, consider disabling or blocking external access to the /api/file/readDir and /api/block/getChildBlocks endpoints at the network or reverse proxy level until the patch can be applied.

Community reactions

The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the information disclosure issue (The Hacker Wire). Social media discussion was noted on Mastodon and Bluesky shortly after disclosure. The vulnerability was also highlighted in the Elest.io self-hosted weekly digest for week 13 of 2026, which noted it alongside other significant CVEs of the period. The reporter credited is CongSec (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management