CVE-2026-104410: SiYuan before 3.8.5 Information Disclosure via /api/export/preview
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.8.5
Event History
Frequently Asked Questions
Who is exposed to this issue?
Instances that allow publish readers to access a public document containing an embedded database view are exposed. The affected data includes database rows marked password-protected or disabled for publishing.
What does an attacker need to exploit it?
An attacker needs access as a publish reader to a public document that embeds a database view. They can request an export preview through the /api/export/preview endpoint; no additional privileges are described.
What information can be disclosed?
The export preview can reveal the primary-key text and cell values of protected database rows. The issue is an information disclosure only; no integrity or availability impact is stated.
Which versions are affected?
SiYuan versions before 3.8.5 are affected. Version 3.8.5 is the first version identified as not affected by the provided information.