Description
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Document Metadata Disclosure
Action: Immediate Patch
AI Analysis

Impact

SiYuan versions up to 3.8.4 allow read‑only token holders to bypass publish access control by calling the getDynamicIcon endpoint with type=8 and crafted content. This flaw permits attackers to retrieve block titles, names, aliases, and hierarchical paths of documents that should be protected, effectively leaking sensitive metadata. The vulnerability is an example of insufficient access control (CWE‑862) and can lead to unauthorized disclosure of organization structure or confidential document identities.

Affected Systems

Affected software is Siyuan Note, a note‑taking application, versions through 3.8.4. The vulnerability resides in the dynamic icon handling routine accessed via the public API endpoint /api/getDynamicIcon. End‑users running these versions, especially those that expose read‑only tokens over a network, are at risk.

Risk and Exploitability

The reported CVSS score is 5.3, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely by sending crafted requests to the icon endpoint with a valid read‑only token, so the risk is moderate for environments that expose the API to untrusted users. Proper access checks are missing, making the condition straightforward once a token is obtained.

Generated by OpenCVE AI on September 19, 2026 at 10:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Siyuan to version 3.8.5 or later where the getDynamicIcon access control check has been restored.
  • If upgrading is not immediately possible, restrict the getDynamicIcon endpoint to trusted networks or block access via a reverse‑proxy rule.
  • Review and tighten read‑only token distribution; revoke any tokens that are exposed or no longer needed and enforce least‑privilege principles.
  • Monitor API logs for unexpected icon requests and investigate suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 10:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Title SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint
First Time appeared B3log
B3log siyuan
Weaknesses CWE-862
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T14:10:37.585Z

Reserved: 2026-09-18T21:56:59.671Z

Link: CVE-2026-93921

cve-icon Vulnrichment

Updated: 2026-09-21T14:10:09.260Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T00:16:57.553

Modified: 2026-09-21T15:17:35.930

Link: CVE-2026-93921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses