CVE-2026-85578: SiYuan through 3.8.1 Authorization Bypass via getFile

Published Sep 4, 2026
·
Updated

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.

Affected Software

1 affected component
SiYuan<=3.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.1Patch Authorization Bypass via getFile
  2. Compensating control

    If immediate upgrade is not possible, restrict access to the SiYuan /api/file/getFile endpoint so that reader-role users cannot call it.

Event History

Sep 4, 2026
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already have a SiYuan reader role. They also need to know the identifier of a notebook configured with Visible:false and the path of a target file within it.

2

What information could be exposed?

A reader can retrieve files from notebooks intended to be hidden, including private workspace files, notebook metadata, and internal configuration files.

3

Which deployments are affected?

SiYuan versions through 3.8.1 are affected where readers can reach the /api/file/getFile endpoint and hidden notebooks are configured with Visible:false.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203