CVE-2026-85578 UNKNOWN

CVE-2026-85578

Published: 2026-09-04

Description

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…