CVE-2026-93921 - SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint
CVE ID :CVE-2026-93921
Published : Sept. 19, 2026, 12:16 a.m. | 4 hours, 52 minutes ago
Description :SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 19, 2026, 12:16 a.m. | 4 hours, 52 minutes ago
Description :SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...