Junglewise Threat Intelligence

CVE-2026-82651: SiYuan missing authorization in history and repo diff endpoints

CVE-2026-82651 · Severity: medium · CVSS 4.9 · Published 2026-08-30

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a personal knowledge management application with note-taking and publishing capabilities. An authenticated administrator can bypass a security guard designed to block access to sensitive files (including plaintext publish passwords and template files) by accessing historical snapshots through the /history and /repo/diff endpoints, potentially exposing credentials and configuration data that should be protected.

Technical details

The vulnerability is a missing authorization check (CWE-862/CWE-200) in two HTTP endpoints: /history/*path and /repo/diff/*path in kernel/server/serve.go. While these endpoints require admin authentication and were meant to be protected by the IsForbiddenAbsPath guard (introduced in a prior advisory GHSA-c8r8-95hg-mp34), they construct file paths independently without calling this guard. An authenticated admin attacker can retrieve historical or diff-view copies of sensitive files such as data/.siyuan/publishAccess.json (containing plaintext publish-mode passwords) and files under data/templates/ that exist in the repository history or diff-checkout directory. The guard successfully protects live file access endpoints but fails to cover these archive/history endpoints. The vulnerability requires admin-level authentication and network access to the affected SiYuan instance (typically port 6806). Patched in version 3.8.1.

Affected products

  • SiYuan SiYuan before 3.8.1

Timeline

  • 2026-08-30: disclosed
  • 2026-08-30: patched: patched in v3.8.1

References

Related threats