CVE-2026-85579
SiYuan before v3.8.2 Information Disclosure via undoState
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
| CWE | CWE-639 |
| Vendor | siyuan-note |
| Product | siyuan |
| Published | Sep 4, 2026 |
Get instant alerts for siyuan-note siyuan
Be the first to know when new medium vulnerabilities affecting siyuan-note siyuan are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N