Medium severity6.5NVD Advisory· Published Sep 5, 2026
CVE-2026-86192
CVE-2026-86192
Description
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.8.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.