SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 13:18
Updated : 2026-09-10 16:18
NVD link : CVE-2026-86192
Mitre link : CVE-2026-86192
CVE.ORG link : CVE-2026-86192
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
