Description
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

SiYuan before version 3.8.5 contains an information disclosure flaw that permits an attacker to retrieve password‑protected or publish‑disabled rows from a database view via the /api/export/preview endpoint. The vulnerability is a lack of authorization enforcement (CWE‑862). An attacker can request an export preview of a public document that embeds a database view, and then receive the primary‑key text and cell values of rows that should remain hidden, thereby leaking sensitive data.

Affected Systems

The note‑taking application Siyuan, produced by Siyuan‑Note, is affected. Any installation running a version older than 3.8.5 is vulnerable when configured to allow public documents with database views. No other product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 8.7 marks this flaw as high severity. EPSS data is not available, and it does not appear in the CISA KEV catalog. The vulnerability can be abused remotely by sending an HTTP request to the /api/export/preview endpoint of a publicly accessible document, so the attack surface is all users with network access to the instance. Once exploited, an attacker gains read access to otherwise protected database rows.

Generated by OpenCVE AI on October 2, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.8.5 or later to remove the missing authorization check.
  • Restrict the /api/export/preview endpoint or limit public documents that embed database views until the issue is fixed.
  • Review and harden access controls so that only authorized users can request export previews of sensitive data.

Generated by OpenCVE AI on October 2, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.
Title SiYuan before 3.8.5 Information Disclosure via /api/export/preview
First Time appeared B3log
B3log siyuan
Weaknesses CWE-862
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:37:54.829Z

Reserved: 2026-10-02T00:44:44.528Z

Link: CVE-2026-104410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:10.520

Modified: 2026-10-02T12:17:10.640

Link: CVE-2026-104410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses