SiYuan before v3.8.2 Information Disclosure via undoState
Published Sep 4, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.28%
Description
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
Affected products
-
- Version 0StatusaffectedConstraints<3.8.2
- Version 3.8.2StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Siyuan-Note | Siyuan | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gf8-q9ch-w732 exploitvendor-advisory
- https://www.vulncheck.com/advisories/siyuan-before-3.8.2-information-disclosure-via-undostate third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gf8-q9ch-w732 | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/siyuan-before-3.8.2-information-disclosure-via-undostate | third-party-advisory |
Change history (0)
No recorded changes yet.