Loading market data...
← Back to CVE feed

CVE-2026-101092

MEDIUM CVSS 5.3 View on NVD ↗

Description

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 28, 2026 22:17 UTC Modified: Sep 28, 2026 22:17 UTC