CVE-2026-93921
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
نوع الضعف
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
المراجع
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.go#L546-L549
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.go#L51
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.go#L485-L526
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838
- https://www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpoint
اكتشف الثغرة قبل أن يكتشفها المهاجم.
سجّل الدخول عبر GitHub وشغّل أول تدقيق لك في أقل من دقيقة. الخطة المجانية لا تتطلب بطاقة ائتمان.