CVE-2026-105205
Deferred Deferred - Pending Action

SiYuan Information Disclosure via Block API

Vulnerability report for CVE-2026-105205, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan before version 3.8.5 has an information disclosure vulnerability where publish-mode readers can access backlink block IDs and reference counts from password-protected or publish-disabled documents. Attackers send POST requests to /api/block/getDocInfo or /api/block/getDocsInfo with a published document ID to retrieve sensitive data like refIDs and refCount from restricted blocks.

Detection Guidance

To detect this vulnerability, monitor network traffic for POST requests to /api/block/getDocInfo or /api/block/getDocsInfo endpoints. Check SiYuan server logs for repeated requests to these endpoints with published document IDs. Use tools like curl to test if these endpoints leak backlink block IDs or reference counts from restricted documents.

Impact Analysis

This vulnerability allows unauthorized users to learn about hidden document structures and relationships without accessing the actual content. Attackers could map out sensitive document connections, potentially identifying protected or unpublished information indirectly. The impact is higher for shared or published documents with restricted backlinks.

Compliance Impact

This vulnerability could violate data confidentiality requirements in GDPR and HIPAA by exposing metadata about restricted documents. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. Unauthorized access to document relationships may constitute a compliance breach depending on the data involved.

Mitigation Strategies

Immediately upgrade SiYuan to version 3.8.5 or later to patch the vulnerability. If upgrading is not possible, restrict access to the /api/block/getDocInfo and /api/block/getDocsInfo endpoints by modifying server configurations or firewall rules. Review and remove unnecessary publish-mode access for users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105205. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart