GHSA-q9wp-phq7-jv7cMediumCVSS 5.3

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view...

Published
August 30, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.

🔗 References (4)