Information Disclosure Vulnerability in SiYuan by SiYuan
CVE-2026-85579
5.3MEDIUM
What is CVE-2026-85579?
An information disclosure vulnerability exists in SiYuan that affects the POST /api/transactions/undoState endpoint. This issue arises when the endpoint reveals the peekMutatedRootIDs list from the global undo-log stack based on a user-supplied root ID. Without proper publish-access visibility filtering, an authenticated user aware of a visible document's root ID can access internal root IDs of other documents, including those that are private or unpublished. This leads to the potential exposure of internal identifiers and cross-document relationships, although the content of the documents themselves remains secure.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
