Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85174— SiYuan before v3.8.2 API Token Exposure via Log File

Quick assessment

Affected
siyuan-note siyuan
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SiYuan v3.8.2 之前的版本在全文搜索请求超过时间阈值时,会将查询参数中的 API 令牌以明文形式记录到可访问的日志文件中。经过身份验证的攻击者可以通过 getFile 端点读取该日志文件,从而恢复管理员 API 令牌,并获得永久的管理员访问权限。

CVSS 8.8 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
siyuan-note siyuan < 3.8.2 affected
3.8.2 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85174

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SiYuan before v3.8.2 API Token Exposure via Log File
Source: CVE Program / CVE List V5
Vulnerability Description
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
siyuan-note siyuan 0 ~ 3.8.2 -

II. Public POCs for CVE-2026-85174

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85174

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85174 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85174

No comments yet


Leave a comment