Description
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an information disclosure caused by missing publish‑access checks in the getCurrentAttrViewImages endpoint. Attackers who possess publish read permissions can invoke this endpoint with an unrendered database identifier obtained from related endpoints. The server then returns file system paths and filenames for image assets that are otherwise inaccessible to that user, leaking potentially sensitive internal locations and file names.

Affected Systems

The flaw affects Siyuan Note software provided by siyuan-note. All releases prior to version 3.8.4 are vulnerable; the vulnerable behavior is observed in the getCurrentAttrViewImages API.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability, and the EPSS score is not available while the issue is not listed in the CISA KEV catalog. Exploitation requires authenticated access with publish reader role and the ability to supply an unrendered database identifier, meaning it is not a public remote exploit but can be carried out by users who can enumerate databases. Once triggered, the endpoint leaks asset paths and filenames that could assist attackers in mapping internal file structures or planning further attacks. The overall risk is considered moderate; however, impact on confidentiality may be significant in environments where image assets contain proprietary or sensitive data.

Generated by OpenCVE AI on September 28, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Siyuan to v3.8.4 or later. This applies the official patch that properly enforces publish‑access checks on the getCurrentAttrViewImages endpoint.
  • Re‑configure or restrict access controls so that only authorized database owners can invoke the getCurrentAttrViewImages API, ensuring that publish readers cannot supply arbitrary database identifiers.
  • After applying the patch, audit the system for any remaining exposure of asset paths or filenames and verify that the endpoint no longer returns sensitive information when accessed by unauthenticated or unauthorized users.

Generated by OpenCVE AI on September 28, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Title SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages
First Time appeared B3log
B3log siyuan
Weaknesses CWE-200
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T22:00:17.864Z

Reserved: 2026-09-27T20:29:07.433Z

Link: CVE-2026-101092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T22:17:30.603

Modified: 2026-09-28T22:17:30.753

Link: CVE-2026-101092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T23:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor