CVE-2026-103762: SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.8.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs read-only publish access or anonymous publish access to SiYuan. No authenticated write permissions are required.
What information can be disclosed?
By POSTing an open notebook ID to one of the affected save-path resolver endpoints, an attacker can obtain the global save-box ID and save-path template. This can reveal the existence and creation time of an unpublished notebook.
Which endpoints are affected?
The affected endpoints are getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath.