CVE-2026-105205: SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo

Published Oct 4, 2026
·
Updated

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.

Affected Software

1 affected component
SiYuan SiYuan<3.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.5

Event History

Oct 4, 2026
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any publish-mode reader can exploit it without authentication or user interaction, provided they can query a published document ID.

2

What information can be exposed?

The affected API endpoints can disclose backlink block IDs and reference counts associated with password-protected or publish-disabled documents that reference a published document.

3

Which configurations are affected?

Deployments are affected when a published document has references from documents intended to remain hidden through password protection or disabled publishing. The issue affects SiYuan versions before 3.8.5.

4

What can be done before upgrading?

Restrict publish-mode access to trusted readers and avoid publishing documents that may be referenced by password-protected or publish-disabled content. Limiting access to the affected API endpoints can also reduce exposure if your deployment permits it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203