Loading market data...
← Back to CVE feed

CVE-2026-104410

HIGH CVSS 7.5 View on NVD ↗

Description

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 18:17 UTC