SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 12:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-85578
Mitre link : CVE-2026-85578
CVE.ORG link : CVE-2026-85578
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
