CVE-2026-105205: SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.8.5
Event History
Frequently Asked Questions
Who can exploit this issue?
Any publish-mode reader can exploit it without authentication or user interaction, provided they can query a published document ID.
What information can be exposed?
The affected API endpoints can disclose backlink block IDs and reference counts associated with password-protected or publish-disabled documents that reference a published document.
Which configurations are affected?
Deployments are affected when a published document has references from documents intended to remain hidden through password protection or disabled publishing. The issue affects SiYuan versions before 3.8.5.
What can be done before upgrading?
Restrict publish-mode access to trusted readers and avoid publishing documents that may be referenced by password-protected or publish-disabled content. Limiting access to the affected API endpoints can also reduce exposure if your deployment permits it.