CVE-2026-101092

⚪ Do wiadomości

Brak kontroli dostępu w SiYuan umożliwia nieautoryzowanym użytkownikom wyciek ścieżek obrazów.

CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-28 22:17:30 UTC
Ostatnia modyfikacja (NVD)2026-10-01 16:17:30 UTC
Referencje