PT-2026-102388 · Siyuan · Siyuan

·

CVE-2026-101092

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description Insufficient publish-access checks in the 'getCurrentAttrViewImages' endpoint allow users with publish reader permissions to retrieve image asset paths from unauthorized databases. By providing an unrendered database identifier obtained via related endpoints, an attacker can leak filenames and image asset paths of detached rows that are normally restricted by the rendering endpoint.
Recommendations Update to version 3.8.4 or later. As a temporary mitigation, restrict access to the 'getCurrentAttrViewImages' endpoint.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101092
GHSA-J9P6-5639-GF4F

Affected Products

Siyuan