Medium severity5.3NVD Advisory· Published Sep 28, 2026· Updated Sep 28, 2026
CVE-2026-101092
CVE-2026-101092
Description
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Affected products
1- Range: <3.8.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.