CVE-2026-93921
published 2026-09-19CVE-2026-93921: SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.38%
29.2th percentile
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | <= 3.8.4 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SiYuan-Note SiYuan up to 3.8.4 GetDynamicIcon Endpoint Type special elements in template engine
vuldb·2026-09-19·CVSS 4.3
CVE-2026-93921 [MEDIUM] SiYuan-Note SiYuan up to 3.8.4 GetDynamicIcon Endpoint Type special elements in template engine
A vulnerability classified as problematic has been found in SiYuan-Note SiYuan up to 3.8.4. This affects an unknown function of the component GetDynamicIcon Endpoint. This manipulation of the argument Type causes improper neutralization of special elements used in a template engine.
This vulnerability appears as CVE-2026-93921. The attack may be initiated remotely. There is no available exploit.
GHSA
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata.
ghsa_unreviewed·2026-09-19
CVE-2026-93921 [MEDIUM] CWE-862 SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata.
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuanhttps://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.go#L546-L549https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.go#L51https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.go#L485-L526https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838https://www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpointhttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838
2026-09-19
Published