Description
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows anonymous readers to access content that should have been hidden, through SQL embed blocks, attribute-view keys, and attribute-view backlinks enabled in publish mode. The failure to filter invisible-tier content permits the disclosure of sensitive data, reducing confidentiality and potentially revealing private information to unauthenticated users. This weakness is categorized as CWE-668, indicating an information exposure flaw.

Affected Systems

Siyuan Note (siyuan-note:siyuan) is affected by all releases before version 3.8.1. Administrators who have marked content as unlisted may still expose it when publishing documents.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability presents moderate risk. An attacker does not need authentication; any anonymous reader can exploit the flaw simply by accessing a published URL. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. However, the ease of exploitation and lack of access control makes it a low‑effort disclosure risk for exposed data.

Generated by OpenCVE AI on August 30, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Siyuan to version 3.8.1 or later to include the vendor‑provided fix.
  • If an immediate update is unavailable, restrict publish mode to trusted users or disable it altogether until a patch is applied.
  • Verify that invisible-tier content is no longer returned in publish listings by testing empty content IDs and monitoring any unexpected data exposure.

Generated by OpenCVE AI on August 30, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
Title SiYuan before v3.8.1 Information Disclosure via Publish Access
First Time appeared B3log
B3log siyuan
Weaknesses CWE-668
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-30T14:33:33.793Z

Reserved: 2026-08-30T13:38:00.102Z

Link: CVE-2026-82652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T15:16:45.900

Modified: 2026-08-30T15:16:45.900

Link: CVE-2026-82652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T15:30:18Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere