PatchSiren cyber security CVE debrief
CVE-2026-82652 siyuan-note CVE debrief
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted. This vulnerability impacts SiYuan deployments with configured invisible content, potentially leading to information disclosure. The issue arises from inadequate filtering mechanisms in the publish mode of affected SiYuan versions. Users should verify their instances and consider applying patches or mitigations. Further verification is needed to confirm affected scope, and defenders should review the official advisory for mitigation steps.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-30
- Original CVE updated
- 2026-08-30
- Advisory published
- 2026-08-30
- Advisory updated
- 2026-08-30
Who should care
Users of SiYuan versions prior to v3.8.1, particularly those who have configured invisible content in their SiYuan instances, should be aware of this vulnerability and take steps to mitigate it. This includes administrators and security teams responsible for maintaining SiYuan deployments, as well as operators who may be impacted by potential information disclosure.
Technical summary
The vulnerability exists in SiYuan versions prior to v3.8.1, where the application fails to properly filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks when in publish mode. This oversight allows anonymous readers to enumerate invisible content, potentially leading to information disclosure, despite administrative configurations that mark such content as unlisted. The issue arises from inadequate filtering mechanisms in the publish mode of affected SiYuan versions.
Defensive priority
Medium priority given the CVSS score of 6.9 and the potential for information disclosure.
Recommended defensive actions
- Inventory and verify affected systems running SiYuan versions prior to v3.8.1
- Apply the vendor-provided patch or upgrade to SiYuan v3.8.1 or later
- Monitor for potential exploitation attempts targeting this vulnerability
- Review and adjust access controls for sensitive content in SiYuan
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description indicates that SiYuan before v3.8.1 has a vulnerability that allows anonymous readers to enumerate invisible content. The NVD entry is currently Received. Further verification is needed to confirm affected scope, and defenders should review the official advisory for mitigation steps. The vulnerability impacts SiYuan deployments with configured invisible content, potentially leading to information disclosure. Users should verify their instances and consider applying patches or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82652 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82652
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82652 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82652
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-2pgf-jv7c-q7rx
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-3.8.1-information-disclosure-via-publish-access
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.