CVE-2026-101092 PUBLISHED

SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 28.09.2026 Updated: 28.09.2026

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor siyuan-note
Product siyuan
Versions Default: unaffected
  • affected from 0 to 3.8.4 (excl.)
  • Version 3.8.4 is unaffected

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE