Junglewise Threat Intelligence

CVE-2026-101092: SiYuan information disclosure in getCurrentAttrViewImages endpoint

CVE-2026-101092 · Severity: medium · CVSS 5.3 · Published 2026-09-28

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge management application. A flaw in the image retrieval endpoint allows users with read-only access to a published knowledge base to leak file paths and names of images stored in databases they should not be able to access. While the actual image content remains protected by a separate check, the disclosure of asset paths and database structure violates the access control model intended for published content.

Technical details

The getCurrentAttrViewImages endpoint fails to apply the top-level publish-access check (CheckAttributeViewBlockAccessableByPublishAccess) that its sibling rendering endpoint enforces, instead relying only on per-row filtering. An attacker with publish-reader access can call the endpoint with an unrendered database identifier to extract image asset paths from detached rows, exploiting the fact that the per-row filter treats detached rows as unconditionally accessible. The vulnerability requires read-only role context (either anonymous in password-less deployments or with a valid publish password) and yields file paths and filenames only, as the static asset route enforces a separate access check preventing image content disclosure.

Affected products

  • SiYuan SiYuan before 3.8.4

Timeline

  • 2026-09-14: disclosed: Security advisory GHSA-j9p6-5639-gf4f and fix commit published
  • 2026-09-14: patched: Fix applied in commit 48229dc76ce4212fe42295393af617947b157c15
  • 2026-09-28: advisory: CVE-2026-101092 published

References

Related threats