← Back to CVE List
CVE-2026-93921NVD
Vulnerability Summary
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
External References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.go#L51
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.go#L485-L526
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.go#L546-L549
- https://www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpoint