CVE-2026-101092: SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A publish reader can exploit it remotely without authentication beyond the publish-reader level. The attacker also needs an unrendered database identifier, which can be obtained through related endpoints.
What information can be exposed?
The vulnerable endpoint can disclose image asset paths and filenames associated with detached rows in databases the publish reader is not authorized to access. It does not provide the rendering access that the rendering endpoint would deny.
Are all versions affected?
Versions of SiYuan before v3.8.4 are affected. Upgrading to v3.8.4 or later addresses the missing publish-access check.