CVE-2026-82652: Siyuan-Note Siyuan

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.

Affected products

Published 2026-08-30. Last modified 2026-08-31.