← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 11:22via CVEFeed

CVE-2026-85174 - SiYuan before v3.8.2 API Token Exposure via Log File

Brief

CVE ID : CVE-2026-85174

Published : Sept. 3, 2026, 11:22 a. m.

  • 1 hour ago

Description : SiYuan before v3.

  • 2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed