Medium severity5.3NVD Advisory· Published Sep 9, 2026
CVE-2026-87810
CVE-2026-87810
Description
Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.8.2+ 1 more
- (no CPE)range: <3.8.2
- (no CPE)range: <3.8.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.