CVE-2026-101092
published 2026-09-28CVE-2026-101092: SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.24%
13.4th percentile
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.4 | 3.8.4 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases.
ghsa_unreviewed·2026-09-29
CVE-2026-101092 [MEDIUM] CWE-200 SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases.
SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.
VulDB
siyuan-note SiYuan up to 3.8.3 getCurrentAttrViewImages improper authorization
vuldb·2026-09-29·CVSS 5.3
CVE-2026-101092 [MEDIUM] siyuan-note SiYuan up to 3.8.3 getCurrentAttrViewImages improper authorization
A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.8.3. This affects an unknown function of the component getCurrentAttrViewImages. The manipulation results in improper authorization.
This vulnerability is known as CVE-2026-101092. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuan/commit/48229dc76ce4212fe42295393af617947b157c15https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j9p6-5639-gf4fhttps://www.vulncheck.com/advisories/siyuan-before-3.8.4-information-disclosure-via-getcurrentattrviewimageshttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-j9p6-5639-gf4f
2026-09-28
Published