CVE-2026-82652
Received Received - Intake

SiYuan Publish Mode Content Enumeration Vulnerability

Vulnerability report for CVE-2026-82652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulnCheck

Description

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siyuan siyuan to 3.8.1 (exc)
siyuan siyuan 3.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan before v3.8.1 fails to filter content marked as invisible by admins in publish mode. This allows anonymous readers to access unlisted content through SQL embed blocks, attribute-view keys, and attribute-view backlinks despite admin settings.

Detection Guidance

To detect this vulnerability, check if SiYuan is running a version prior to 3.8.1. Inspect published content for SQL embed blocks, attribute-view keys, and attribute-view backlinks that should be marked invisible. Test anonymous access in publish mode to see if these elements expose unlisted content.

Impact Analysis

If you use SiYuan in publish mode with content marked invisible, anonymous users could enumerate and access this unlisted content. This may expose sensitive information unintentionally, depending on what was marked invisible.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) or HIPAA (health information privacy) if unlisted content contains protected information. Compliance may be impacted due to improper access controls.

Mitigation Strategies

Upgrade SiYuan to version 3.8.1 or later to apply the fix for invisible-tier content filtering. Review published content to ensure no unlisted data is exposed. Disable publish mode temporarily if an upgrade is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart