CVE-2026-85578

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 12:17

Updated : 2026-09-14 14:17


NVD link : CVE-2026-85578

Mitre link : CVE-2026-85578

CVE.ORG link : CVE-2026-85578


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization