SiYuan 存在一个信息泄露漏洞(在 v3.8.1 中确认存在,并在 v3.8.2 中修复),影响位于读者可访问的 端点。该端点在接收到调用方提供的根 ID(root ID)后,会直接返回全局撤销日志堆栈中的 列表,且未应用发布访问的可见性过滤机制。因此,知道某可见文档根 ID 的已认证读者,可以获取在同一跨文档事务中被修改的其他文档(包括私有或未发布文档)的内部根 ID,从而泄露内部标识符及跨文档关联关系。不过,文档正文内容并未直接暴露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85584 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85585 | 7.5 HIGH | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85583 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85582 | 6.5 MEDIUM | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85580 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
No comments yet