{"id":"CVE-2026-93921","title":"SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata","summary":"SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-862"],"vendor":"siyuan-note","product":"github.com/siyuan-note/siyuan/kernel","affected":["github.com/siyuan-note/siyuan/kernel <= 3.8.4"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:17:35.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93921","references":[{"url":"https://github.com/siyuan-note/siyuan","label":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/icon.go#L546-L549","label":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/api/router.go#L51","label":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/template.go#L485-L526","label":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-through-3.8.4-access-control-bypass-via-dynamic-icon-endpoint","label":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-whcx-xxqh-c838","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00378,"epssPercentile":0.29073,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T14:10:30.546665Z"},"ingestedAt":"2026-09-18T23:54:36.626Z","slug":"CVE-2026-93921","body":"## Overview\n\nSiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":36,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":208420,"id":"CVE-2026-93921","ts":1790001593130,"field":"exploit_available","old":"false","new":"true"}]}