CVE-2026-82652
published 2026-08-30CVE-2026-82652: SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.34%
25.2th percentile
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.1 | 3.8.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.8.0 Publish Mode information disclosure
vuldb·2026-08-30·CVSS 5.3
CVE-2026-82652 [MEDIUM] siyuan-note SiYuan up to 3.8.0 Publish Mode information disclosure
A vulnerability was found in siyuan-note SiYuan up to 3.8.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Publish Mode. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2026-82652. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode.
ghsa_unreviewed·2026-08-30
CVE-2026-82652 [MEDIUM] CWE-668 SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode.
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-30
Published