天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-101092 SiYuan 访问控制绕过漏洞

影响未授权读者可获取受限数据库中的图片路径与文件名

AI 研判

SiYuan 在 v3.8.4 之前版本的 getCurrentAttrViewImages 接口未正确执行发布访问权限校验。发布读者可借助相关接口获取未渲染的数据库标识,进而调用该接口读取本应被拒绝的数据库图片资源路径。

影响范围

SiYuan

SiYuan v3.8.4 之前的版本,具体受影响版本范围以官方公告为准。

漏洞详情

该漏洞属于访问控制缺失(越权读取)。getCurrentAttrViewImages 接口在返回图片资源路径前未校验调用者是否具备对应数据库的发布访问权限,攻击者可先通过关联接口拿到未渲染的数据库标识,再请求该接口获取 detached-row 图片的资源路径与文件名,而这些内容在正常渲染接口中会被拒绝。

利用条件与风险

利用需目标实例开启发布服务且攻击者具备发布读者身份,属于信息泄露类风险,不直接导致代码执行,但可能暴露敏感图片资源路径。

修复建议

升级至 SiYuan v3.8.4 或更高版本;若无法立即升级,可限制发布服务的访问范围或暂时关闭发布功能以降低风险。

原始情报

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint with an unrendered database identifier obtained through related endpoints to leak detached-row image asset paths and filenames that the rendering endpoint would deny.