Security Advisory
CVE-2026-86192
6.5
MEDIUM
Vulnerability Description
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Published Date
September 5, 2026
Official Source
NIST NVD Advisory