Authorization Bypass in SiYuan Note by SiYuan Technology
CVE-2026-85578
7.1HIGH
What is CVE-2026-85578?
SiYuan Note versions up to 3.8.1 are susceptible to an authorization bypass vulnerability affecting the /api/file/getFile endpoint. This flaw enables users with reader roles to access files from notebooks that are intended to be private and configured with 'Visible:false'. By exploiting knowledge of the hidden notebook identifier and file path, unauthorized users can retrieve sensitive information including notebook metadata and internal configurations, undermining the confidentiality of private workspaces.
Affected Version(s)
siyuan 0 <= 3.8.1
