Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages. | |
| Title | Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-09T11:20:58.911Z
Updated: 2026-09-09T11:20:58.911Z
Reserved: 2026-09-09T10:30:15.669Z
Link: CVE-2026-87810
No data.
Status : Deferred
Published: 2026-09-09T12:17:15.797
Modified: 2026-09-09T20:20:21.673
Link: CVE-2026-87810
No data.