Junglewise Threat Intelligence

CVE-2026-93921: SiYuan access control bypass in getDynamicIcon endpoint

CVE-2026-93921 · Severity: medium · CVSS 4.3 · Published 2026-09-19

Technologies: SiYuan Note SiYuan. Vendors: SiYuan Note.

Executive brief

SiYuan is an open-source knowledge management and note-taking workspace application. An access control vulnerability in versions through 3.8.4 allows users with read-only access tokens to retrieve sensitive document metadata (titles, names, aliases, and document hierarchies) that should be restricted. An attacker with a limited read-only token can exploit template injection to access confidential document information.

Technical details

The getDynamicIcon endpoint fails to enforce publish access control, allowing read-only token holders to inject crafted content with type=8 parameters to trigger template injection. This enables unauthorized metadata extraction including block titles, names, aliases, and hierarchical paths of restricted documents. The vulnerability requires network access and a valid read-only token, and no user interaction is necessary.

Affected products

  • SiYuan Note SiYuan through 3.8.4

Timeline

  • 2026-09-19: disclosed

References

Related threats