CVE-2026-87810
Deferred Deferred - Pending Action

Information Disclosure in Siyuan Notes App

Vulnerability report for CVE-2026-87810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Siyuan before v3.8.2 allows unauthenticated users in publish mode to submit arbitrary search terms to the POST /api/search/fullTextSearchBlock endpoint. While the endpoint filters out private blocks from search results, it still returns unfiltered match counts (like the number of matching blocks and pages). This lets attackers determine if specific terms exist in hidden or unpublished documents without seeing the actual content.

Detection Guidance

To detect this vulnerability, monitor network traffic for POST requests to the /api/search/fullTextSearchBlock endpoint in Siyuan's publish mode. Check if responses include unfiltered match counts (matchedBlockCount, matchedRootCount, pageCount) for private documents. Use tools like Wireshark or tcpdump to capture and analyze HTTP POST requests targeting this endpoint.

Impact Analysis

An attacker could use this to learn whether sensitive or confidential information exists in your private notes. They can determine the number of matching blocks and pages for specific terms, which may help them infer the presence of restricted content. This could lead to data exposure or targeted attacks if the information is sensitive.

Compliance Impact

This vulnerability could violate compliance requirements that mandate protection of sensitive data, such as GDPR's data confidentiality principles or HIPAA's safeguards for protected health information. Unauthorized disclosure of whether restricted content exists may constitute a breach of these regulations, potentially leading to legal and financial penalties.

Mitigation Strategies

Immediately upgrade Siyuan to version 3.8.2 or later to patch the vulnerability. If upgrading is not possible, disable the /api/search/fullTextSearchBlock endpoint in publish mode or restrict access to it via network-level controls. Monitor for unusual search queries that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart