CVE-2026-85174 - SiYuan before v3.8.2 API Token Exposure via Log File
Brief
CVE ID : CVE-2026-85174
Published : Sept. 3, 2026, 11:22 a. m.
- 1 hour ago
Description : SiYuan before v3.
- 2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
