CVE-2026-86192: SiYuan before v3.8.2 Information Disclosure via Attribute-View

Published Sep 5, 2026
·
Updated

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.

Affected Software

1 affected component
SiYuan SiYuan<3.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in v3.8.2
  2. Compensating control

    If upgrading to SiYuan v3.8.2 is not immediately possible, restrict network/API access to the getAttributeViewKeys endpoint so unauthenticated or unauthorized users cannot retrieve attribute-view KeyValues.

Event History

Sep 5, 2026
CVE Published
via MITRE·12:09 PM
Data Sourced
via MITRE·12:09 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user with publish-reader access can exploit the affected endpoint. The issue does not require user interaction, but it does require low-level privileges.

2

What data can be exposed?

Hidden KeyValues payloads associated with attribute-view rows bound to documents the reader cannot access may be returned. This can disclose private database contents.

3

Which deployments are affected?

SiYuan versions before v3.8.2 are affected. Deployments that grant publish-reader access and use attribute views containing rows linked to inaccessible documents are exposed.

4

How can I determine whether exposure is possible?

Review whether publish readers can call the getAttributeViewKeys endpoint and whether attribute-view rows reference documents those readers are not permitted to view. If both conditions exist on a version before v3.8.2, private cell values may be accessible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203