PT-2026-85478 · Siyuan · Siyuan
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.2
Description
An authorization bypass exists in the '/api/file/getFile' endpoint. Users with a reader role can retrieve files from notebooks configured as
Visible:false if they know the hidden notebook identifier and the file path. This allows unauthorized access to private workspace files, including internal configuration and notebook metadata.Recommendations
Update to version 3.8.2 or later.
Restrict access to the '/api/file/getFile' endpoint to minimize the risk of unauthorized file retrieval.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan