Medium severity4.3NVD Advisory· Published Sep 19, 2026· Updated Sep 19, 2026
CVE-2026-93921
CVE-2026-93921
Description
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Affected products
1- Range: <=3.8.4
Patches
Vulnerability mechanics
References
5- github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.gonvd
- github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.gonvd
- github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.gonvd
- github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838nvd
- www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpointnvd
News mentions
0No linked articles in our index yet.