思源笔记(SiYuan)3.8.4 及之前版本在 端点中未能正确执行发布访问控制,导致持有只读令牌的持有者可以访问文档元数据。攻击者可以通过在 端点传入 和特制的 参数,利用模板注入读取受限文档的区块标题、名称、别名以及层级路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93922 | 8.8 HIGH | SiYuan through 3.8.4 Stored XSS via notebook names |
| CVE-2026-93923 | 8.8 HIGH | SiYuan through 3.8.4 Stored XSS via Heading Style Attribute |
| CVE-2026-93591 | 7.6 HIGH | SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go |
No comments yet