Security Advisory

CVE-2026-85578

6.5
MEDIUM

Vulnerability Description

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
Published Date September 4, 2026
Official Source NIST NVD Advisory