Junglewise Threat Intelligence

CVE-2026-85174: SiYuan API token exposure in log file

CVE-2026-85174 · Severity: high · CVSS 8.8 · Published 2026-09-03

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge management application. When users perform full-text search queries on large datasets, the application logs the complete search request—including any API authentication tokens passed in the URL—to a plaintext log file. Any authenticated user can retrieve this log file, exposing admin API tokens and granting attackers permanent administrative access to the application and its data.

Technical details

The vulnerability stems from the Timing middleware in kernel/model/session.go:484, which logs the full HTTP request URI (including query parameters) when POST /api/search/fullTextSearchBlock requests exceed 15 seconds. Admin tokens passed via the ?token= query parameter are written unmasked to /temp/siyuan.log, which is not protected by the IsForbiddenAbsPath() access control list. Any authenticated user can retrieve this log file via the POST /api/file/getFile endpoint, recovering admin API tokens. The timing threshold is routinely exceeded in production on large workspaces, ensuring tokens are reliably logged. The fix involves logging only the path (c.Request.URL.Path) instead of the full URI, and adding /temp/siyuan.log to the forbidden paths list as defense-in-depth.

Affected products

  • SiYuan SiYuan before 3.8.2

Timeline

  • 2026-08-19: disclosed: GitHub security advisory published
  • 2026-09-03: advisory: CVE-2026-85174 assigned and published on NVD
  • 2026-09-03: patched: Fix available in v3.8.2

References

Related threats