思源笔记(SiYuan)在 v3.8.5 之前的版本中存在一个缺失授权验证的漏洞,该漏洞出现在 、 和 接口中。此漏洞允许具有只读发布权限的访客获取未发布的笔记本盒(notebook box)ID。具有只读发布访问权限或匿名访问权限的攻击者,可以通过向任意公开的笔记本 ID 发送 POST 请求,从而获取全局保存盒 ID 和保存路径模板,进而暴露隐藏笔记本的存在及其创建时间。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.5 |
affected |
3.8.5 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104410 | 7.5 HIGH | SiYuan before 3.8.5 Information Disclosure via /api/export/preview |
| CVE-2026-103763 | 5.8 MEDIUM | SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo |
No comments yet