Access Control Bypass in SiYuan Product by SiYuan Note
CVE-2026-93921
5.3MEDIUM
What is CVE-2026-93921?
In SiYuan versions up to 3.8.4, a security issue exists where the system does not properly enforce publish access controls within the getDynamicIcon endpoint. This vulnerability allows users with read-only tokens to manipulate the endpoint. An attacker can exploit this by using a crafted request with type=8 to gain unauthorized access to document metadata, including block titles, names, aliases, and hierarchical paths of restricted documents. This can lead to unauthorized exposure of sensitive information through template injection techniques.
Affected Version(s)
siyuan 0 <= 3.8.4
