思源笔记(SiYuan)在 v3.8.5 版本之前存在一个信息泄露漏洞,该漏洞允许只读的发布读者通过 getNotebookInfo 端点获取被排除在发布范围外的文档的元数据。攻击者,包括在未设置读者密码时的匿名访问者,可以通过查询可发布的笔记本,获取被隐藏文档的文档数量、大小以及修改时间戳。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.5 |
affected |
3.8.5 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104410 | 7.5 HIGH | SiYuan before 3.8.5 Information Disclosure via /api/export/preview |
| CVE-2026-103762 | 5.3 MEDIUM | SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints |
No comments yet