CVE-2026-82652: SiYuan before v3.8.1 Information Disclosure via Publish Access
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.8.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
SiYuan instances running a version before v3.8.1 with publish mode content accessible to anonymous readers are exposed. Content configured by an administrator as unlisted can still be enumerated through the affected listing mechanisms.
What does an attacker need to exploit it?
No authentication, privileges, or user interaction are required. An anonymous reader can use SQL embed blocks, attribute-view keys, or attribute-view backlinks to enumerate invisible-tier content.
Is the impact limited to a particular kind of content?
The disclosed content is invisible-tier content that administrators intended to keep unlisted in publish mode. The issue affects its exposure through SQL embed blocks, attribute-view keys, and attribute-view backlinks.
How can I determine whether my deployment is affected?
Check whether the SiYuan version is earlier than v3.8.1 and whether publish mode permits anonymous access. Then assess whether published content uses SQL embed blocks, attribute views or attribute-view backlinks that could list invisible-tier content.