CVE-2026-87810: Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock

Published Sep 9, 2026
·
Updated

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages.

Affected Software

1 affected component
SiYuan<3.8.2

Event History

Sep 9, 2026
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

SiYuan instances running a version before 3.8.2 that allow unauthenticated access in publish mode are exposed. An unauthenticated publish-mode reader can query the affected search endpoint.

2

What does an attacker need to exploit it?

The attacker needs network access to the SiYuan instance and the ability to send POST requests to /api/search/fullTextSearchBlock. No authentication, privileges, or user interaction are required.

3

What information can be disclosed?

The endpoint does not return private blocks themselves, but its unfiltered match counts reveal whether chosen search terms occur in hidden or unpublished documents. The counts can disclose the number of matching blocks and pages.

4

How can the issue be mitigated if upgrading is not immediately possible?

Restrict or disable unauthenticated publish-mode access so untrusted users cannot submit searches to the affected endpoint. Limiting network access to trusted users also reduces exposure.

5

How can administrators determine whether they are affected?

Check whether the instance is running a version before 3.8.2 and exposes publish mode to unauthenticated readers. On an affected instance, searches through the endpoint may show match counts for terms that exist only in hidden or unpublished content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203