CVE-2026-101092
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | 0 < 3.8.4 | affected |
| siyuan-note | siyuan | 3.8.4 | unaffected |
Weaknesses
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j9p6-5639-gf4f
- https://github.com/siyuan-note/siyuan/commit/48229dc76ce4212fe42295393af617947b157c15
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-information-disclosure-via-getcurrentattrviewimages
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.