SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization. | |
| Title | SiYuan before v3.8.2 Information Disclosure via Attribute-View | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-05T12:09:06.781Z
Updated: 2026-09-05T12:09:06.781Z
Reserved: 2026-09-05T11:51:31.102Z
Link: CVE-2026-86192
No data.
Status : Deferred
Published: 2026-09-05T13:18:14.443
Modified: 2026-09-08T20:05:53.177
Link: CVE-2026-86192
No data.