Vulnerabilities & PatchesEmerging1 src
CVE-2026-85174 - SiYuan before v3.8.2 API Token Exposure via Log File
CVE ID : CVE-2026-85174
Published : Sept. 3, 2026, 11:22 a. m.
• 1 hour ago
Description : SiYuan before v3. 8. 2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
Severity: 8.8
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...