Junglewise Threat Intelligence

CVE-2026-87809: Siyuan information disclosure in export preview and copyStdMarkdown

CVE-2026-87809 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

Siyuan is a note-taking and document management system. The application fails to properly filter private or publish-disabled content before rendering it in two public-facing API endpoints used for exporting and previewing documents. An attacker with basic reader access can retrieve the full content of private blocks embedded in public documents, leading to unauthorized disclosure of sensitive information.

Technical details

The /api/export/preview and /api/lute/copyStdMarkdown endpoints resolve embedded block queries before applying publish-access filtering, allowing unauthorized disclosure. The vulnerability exists because the embed resolver (resolveEmbedR) executes SQL queries to fetch blocks without checking the caller's publish-access context, and the FilterContentByPublishAccess filter—applied after rendering—cannot distinguish embedded private content from the root document's legitimate content. An authenticated reader needs only the ID of a public document containing an embed query that selects private blocks to trigger the disclosure; no direct access to the private document is required. The issue was fixed in v3.8.2 by applying publication filtering before embed resolution.

Affected products

  • Siyuan Siyuan before 3.8.2

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in v3.8.2

References

Related threats