CVE-2026-101092
Deferred Deferred - Pending Action

SiYuan Publish-Access Bypass Exposes Image Asset Paths

Vulnerability report for CVE-2026-101092, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulnCheck

Description

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan before v3.8.4 has a flaw in the getCurrentAttrViewImages endpoint where publish-access checks are not properly enforced. This allows users with publish reader permissions to retrieve image asset paths from databases they should not access. Attackers exploit this by using an unrendered database identifier from other endpoints to leak image paths and filenames that would normally be blocked by the rendering endpoint.

Detection Guidance

This vulnerability involves unauthorized access to image asset paths via the getCurrentAttrViewImages endpoint in SiYuan before v3.8.4. Detection requires checking for unusual API calls to this endpoint with unrendered database identifiers. Monitor server logs for requests to /api/getCurrentAttrViewImages with parameters indicating database access outside normal rendering contexts.

Impact Analysis

This vulnerability could allow unauthorized users to access sensitive image files stored in databases they do not have permission to view. If exploited, attackers might obtain file paths and filenames, potentially leading to further data breaches or unauthorized access to confidential information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive image asset paths and filenames from unauthorized databases. Unauthorized access to such data may violate confidentiality requirements under these regulations, particularly if the exposed data includes personally identifiable information or protected health information.

Mitigation Strategies

Upgrade SiYuan to version v3.8.4 or later to address the publish-access check vulnerability. Ensure no unauthorized database identifiers are exposed through related endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101092. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart