CVE-2026-103763: SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo

Published Oct 2, 2026
·
Updated

SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain document count, size and modification timestamps of hidden documents.

Affected Software

1 affected component
SiYuan SiYuan<3.8.5

Event History

Oct 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any read-only publish reader can query publish-visible notebooks. If no reader password is configured, anonymous visitors can do so.

2

What information can be exposed?

The endpoint can reveal metadata for documents excluded from publishing, including document counts, sizes, and modification timestamps. The available data describes metadata disclosure only, not disclosure of the hidden document contents.

3

Which deployments are affected?

SiYuan versions before v3.8.5 are affected where publish-visible notebooks are accessible to read-only readers. Exposure is greatest when published content has no reader password because anonymous visitors can make the queries.

4

How can I tell whether my instance is exposed?

Check whether the SiYuan version is earlier than v3.8.5 and whether publish-visible notebooks contain documents excluded from publishing. Also determine whether reader access is password-protected; without a password, anonymous users may be able to query the affected endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203