HIGH 8.7 NVD
CVE-2026-85174
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authe
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3wvc-5754-gp67
- https://www.vulncheck.com/advisories/siyuan-before-3.8.2-api-token-exposure-via-log-file
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-03 via NVD.
vulnfeed aggregates 7805 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.