CVE-2026-93921: SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint

Published Sep 18, 2026
·
Updated

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.

Affected Software

1 affected component
SiYuan<=3.8.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.4
  2. Compensating control

    Mitigate by preventing access to the SiYuan getDynamicIcon endpoint (the dynamic icon endpoint) for users holding only read-only tokens, e.g., via network/ACL/WAF rules that block those requests until the access control bypass is fixed.

Event History

Sep 18, 2026
CVE Published
via MITRE·11:12 PM
Data Sourced
via MITRE·11:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs a read-only SiYuan token. The vulnerable endpoint is network-accessible and requires no user interaction.

2

What information can be exposed?

A read-only token holder can retrieve metadata for restricted documents, including block titles, names, aliases, and hierarchical paths. The provided information does not indicate exposure of full document contents.

3

Which deployments are affected?

SiYuan versions through 3.8.4 are affected. Deployments are exposed where read-only tokens exist and can reach the getDynamicIcon endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203