PT-2026-85479 · Siyuan · Siyuan

·

CVE-2026-85579

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.2
Description An information disclosure issue exists in the reader-accessible POST '/api/transactions/undoState' endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents, including private or unpublished ones, that were modified in the same cross-document transaction. This discloses internal identifiers and cross-document relationships, although document body contents are not directly exposed.
Recommendations Update to version 3.8.2.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85579
GHSA-6GF8-Q9CH-W732

Affected Products

Siyuan