
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33669 is an arbitrary document reading vulnerability in SiYuan, a personal knowledge management system developed by b3log. Prior to version 3.6.2, unauthenticated attackers could enumerate document IDs via the /api/file/readDir interface and then retrieve the full content of all documents — including encrypted or access-restricted ones — via the /api/block/getChildBlocks interface. The vulnerability was disclosed on March 23, 2026, and patched in version 3.6.2. It carries a CVSS v3.1 base score of 9.8 (Critical) per the GitHub Security Advisory, though Feedly's NVD-sourced data notes a score of 7.5 (High) focused solely on confidentiality impact (GitHub Advisory, GHSA Database).
The vulnerability stems from missing access controls on two API endpoints within SiYuan's publishing service. An attacker first calls the /api/file/readDir endpoint to enumerate document IDs without authentication, then submits those IDs to the /api/block/getChildBlocks endpoint via HTTP POST to retrieve full document block content — including content that should be encrypted or restricted. The flaw is classified as CWE-125 (Out-of-bounds Read), though the practical exploitation behavior is more accurately described as an improper authorization / missing authentication for critical function issue. A public proof-of-concept Python script is available that automates both steps (GitHub Advisory, GHSA Database).
Successful exploitation allows an unauthenticated remote attacker to read the full content of all documents stored within a SiYuan publishing service instance, including documents that are encrypted or otherwise access-restricted. The primary impact is a complete loss of confidentiality for all knowledge base content, which may include sensitive personal notes, credentials, or proprietary information. There is no direct integrity or availability impact, though exposure of sensitive document content could facilitate further targeted attacks (GitHub Advisory, Feedly).
A public proof-of-concept Python exploit script is available within the GitHub Security Advisory itself, demonstrating automated document enumeration and content extraction with no authentication required (GitHub Advisory). The EPSS score is approximately 0.023% (0.000430 per Feedly), placing it in the 7th percentile for near-term exploitation likelihood. There is currently no evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The attack requires no privileges, no user interaction, and is exploitable over the network with low complexity (GHSA Database).
/api/file/readDir endpoint to list directory contents and retrieve document IDs (typically alphanumeric block IDs used by SiYuan's internal data model)./api/block/getChildBlocks with the payload {"id": "<doc_id>"} and Content-Type: application/json.markdown or content fields from each returned block object, reconstructing the full document content. Optionally save results to a local JSON file for offline analysis./api/block/getChildBlocks from external or unexpected IP addresses; repeated unauthenticated requests to /api/file/readDir for directory enumeration; high-volume sequential API calls suggesting automated document harvesting./api/file/readDir and /api/block/getChildBlocks from the same source IP without authentication tokens; requests with Content-Type: application/json bodies containing only an id field targeting the block API.Upgrade SiYuan to version 3.6.2 or later, which patches the unauthorized access to the affected API endpoints (GitHub Advisory). As an interim workaround, restrict network access to the SiYuan instance to trusted users or networks only (e.g., via firewall rules or binding the service to localhost). Additionally, consider disabling or blocking external access to the /api/file/readDir and /api/block/getChildBlocks endpoints at the network or reverse proxy level until the patch can be applied.
The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the information disclosure issue (The Hacker Wire). Social media discussion was noted on Mastodon and Bluesky shortly after disclosure. The vulnerability was also highlighted in the Elest.io self-hosted weekly digest for week 13 of 2026, which noted it alongside other significant CVEs of the period. The reporter credited is CongSec (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."