Information Disclosure in SiYuan Prior to 3.8.5
CVE-2026-105205
6.9MEDIUM
What is CVE-2026-105205?
An information disclosure vulnerability in SiYuan prior to version 3.8.5 allows unauthorized users to access sensitive details related to password-protected and publish-disabled documents. By querying a published document, an attacker can utilize specific API endpoints (/api/block/getDocInfo and getDocsInfo) to extract refIDs and refCounts for hidden referencing blocks. This flaw exposes critical information, enabling publish-mode readers to bypass the intended confidentiality settings of documents.
Affected Version(s)
siyuan 0 < 3.8.5
siyuan 3.8.5
