CVE-2026-87809

Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of private, hidden, or publish-disabled blocks by accessing public documents containing embed queries that select those blocks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 12:17

Updated : 2026-09-09 20:20


NVD link : CVE-2026-87809

Mitre link : CVE-2026-87809

CVE.ORG link : CVE-2026-87809


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key