CVE-2026-93921
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Fraqueza
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Referências
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.go#L546-L549
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.go#L51
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.go#L485-L526
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838
- https://www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpoint
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.