PT-2026-83578 · Siyuan · Siyuan
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.1
Description
In publish mode, the software fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks. This allows anonymous readers to enumerate content that has been marked as unlisted by the administrator.
Recommendations
Update to version 3.8.1 or later.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan