HIGH 7.1 NVD
CVE-2026-85578
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks expli
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-8ggq-wq3f-vxrw
- https://www.vulncheck.com/advisories/siyuan-through-3.8.1-authorization-bypass-via-getfile
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.