---
id: CVE-2026-86191
title: >-
  SiYuan versions before v3.8.2 contain an information disclosure vulnerability
  in the getAttributeViewKeysByID endpoint that allows publish readers to
  enumerate private attribute view key definitions without verifying parent
  database visi…
summary: >-
  SiYuan versions before v3.8.2 contain an information disclosure vulnerability
  in the getAttributeViewKeysByID endpoint that allows publish readers to
  enumerate private attribute view key definitions without verifying parent
  database visi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.2
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:05:53.177'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86191'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4qq-w6qx-6839
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-private-attribute-view-key-enumeration
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4qq-w6qx-6839
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T18:08:42.585420Z'
epss: 0.00168
epssPercentile: 0.06518
ingestedAt: '2026-09-06T08:52:34.938Z'
---

## Overview

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
