Security Advisory
CVE-2026-85578
6.5
MEDIUM
Vulnerability Description
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
Published Date
September 4, 2026
Official Source
NIST NVD Advisory