Sceawere

Vulnerability Detail

CVE-2026-104410UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Information Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T12:17:10.520Z",
  "pubdate": "2026-10-02T12:17:10.520Z",
  "executiveSummary": "SiYuan versions prior to 3.8.5 are susceptible to an information disclosure vulnerability located within the /api/export/preview endpoint. This flaw permits unauthorized readers of published documents to bypass access controls, specifically those protecting database rows marked as password-protected or disabled for public viewing. The vulnerability stems from improper input handling and insufficient authorization checks when generating document exports. An attacker can leverage this oversight to exfiltrate sensitive data, including primary-key text and specific cell values contained within database views embedded in public documents. The risk is significant as it undermines the privacy constraints configured by the document author, effectively leaking restricted information to any user with access to the public-facing export interface. No complex authentication is required to trigger this disclosure, as the endpoint processes the request for the embedded view automatically. Organizations relying on SiYuan for document management should prioritize updating to version 3.8.5 or later to remediate the flaw and prevent unauthorized data extraction.",
  "technicalDetails": "The vulnerability resides within the /api/export/preview endpoint, which is designed to render a preview of a document for export purposes. In SiYuan versions before 3.8.5, the server-side logic responsible for processing these requests fails to validate the access permissions of the database rows included within a document's embedded database view.\nRoot Cause: The root cause is a deficiency in the authorization enforcement mechanism. While the main document may be set to public, the application fails to intersect the user's access rights with the security attributes (password protection and 'publish-disabled' status) of individual database rows when rendering the export preview. The application effectively treats the export generation process as a trusted internal operation that ignores the granular access control lists assigned to specific database entries.\nExploitation Method: An attacker can exploit this by navigating to a public document that embeds a database view. By requesting an export preview of the document via the /api/export/preview endpoint, the attacker forces the backend to populate the export data structure with rows that the user should not have permission to view. Because the application logic does not filter the result set based on row-level security policy during the export preview generation, the server serializes the restricted row content into the output buffer.\nAttack Flow: 1. The attacker accesses a public document containing an embedded database view. 2. The attacker triggers the export preview functionality, which invokes the /api/export/preview endpoint. 3. The backend processes the request and fetches the database records associated with the view. 4. The vulnerable function fails to evaluate the 'password-protected' or 'publish-disabled' flags for these records. 5. The server includes the sensitive primary-key text and cell data in the rendered preview response. 6. The attacker captures the response body and extracts the sensitive data.\nImpact: Successful exploitation results in the exposure of sensitive, restricted database content that the document owner intended to keep private. This effectively nullifies security configurations regarding document publication and database visibility, potentially leading to the unauthorized disclosure of confidential information stored within the platform."
}
CVE-2026-104410: SiYuan Information Disclosure Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere