CVE-2026-101092

CVE-2026-101092 published: SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier ...

View full NVD advisory → ← Back to CVE watch