CVE-2026-85174 - SiYuan before v3.8.2 API Token Exposure via Log File
CVE ID :CVE-2026-85174
Published : Sept. 3, 2026, 11:22 a.m. | 1 hour, 41 minutes ago
Description :SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 3, 2026, 11:22 a.m. | 1 hour, 41 minutes ago
Description :SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...