CVE-2026-93921 UNKNOWN

CVE-2026-93921

Published: 2026-09-19

Description

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…