CVE-2026-85174: SiYuan before v3.8.2 API Token Exposure via Log File

Published Sep 3, 2026
·
Updated

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.

Affected Software

1 affected component
SiYuan<v3.8.2

Event History

Sep 3, 2026
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already be authenticated to SiYuan and able to make full-text search requests. They can trigger requests that exceed timing thresholds, then use the getFile endpoint to read the accessible log file.

2

What is the impact after exploitation?

The attacker can recover administrator API tokens written in plaintext to logs. Those tokens can provide permanent administrative access, with high impact to confidentiality, integrity, and availability.

3

Which versions need remediation?

SiYuan versions before 3.8.2 are affected. Upgrade to version 3.8.2 or later.

4

How can I determine whether tokens may already have been exposed?

Review accessible SiYuan log files for API tokens recorded in full-text search query parameters, particularly for searches that exceeded timing thresholds. Any administrator API token found in those logs should be treated as exposed.

5

What should be done if exposure is suspected?

Treat recovered administrator API tokens as compromised and rotate or invalidate them to remove persistent administrative access. Restrict authenticated access and access to the getFile endpoint until the affected version is remediated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203