---
id: CVE-2026-101092
title: >-
  SiYuan before v3.8.4 fails to enforce publish-access checks in the
  getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image
  asset paths from unauthorized databases
summary: >-
  SiYuan before v3.8.4 fails to enforce publish-access checks in the
  getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image
  asset paths from unauthorized databases. Attackers can call the endpoint with
  an unrendered …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.4
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T22:17:30.753'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101092'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/commit/48229dc76ce4212fe42295393af617947b157c15
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j9p6-5639-gf4f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.4-information-disclosure-via-getcurrentattrviewimages
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T22:22:13.607Z'
---

## Overview

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
