The CVE-2026-105205 vulnerability in SiYuan allowed readers of a published page to view document metadata that was kept private or password-protected. The flaw exposed block identifiers and citation counts, not the content of the documents, as the official security bulletin clarifies .

SiYuan is a note-taking and knowledge organization application that can be hosted on the user's own infrastructure. The functionality in question concerns the publishing of notes on the web: the administrator can make some documents publicly available, while others remain disabled or password-protected. In such installations, document metadata needs the same segregation of access as the content itself.
According to the project's security report, the POST /api/block/getDocInfo and POST /api/block/getDocsInfo returned citation data for a document that was indeed public. However, the results could also include blocks from other notes that had not been published. Thus, the vulnerability allowed the document metadata of a public page to be cross-referenced with non-public material.
See also: SiYuan 3.8.4: Stored XSS and two serious vulnerabilities
Which document metadata was exposed?
The response included the block identifiers that referenced the public document, as well as their number. Thus, an external reader could infer that there were hidden notes and how many of them were linked to a published page. The identifiers also contained information about the time the blocks were created. Document metadata does not equal full access, but it does reveal the structure of the notes.
The report emphasizes that the vulnerability did not expose the text of private notes. The report concerned document metadata, not their content itself. The distinction is important for assessing the risk, without negating the violation of the publication limits set by the administrator.
Access did not require an administrator account. The security report notes that a reader role in the publishing mode or, on a website without password protection, even offline access was sufficient. The requester had to know the ID of a document that was already public and request its information from the corresponding API.
's entry for CVE-2026-105205 shows a CVSS-B score of 6.9, which is medium severity, with its data attributed to VulnCheck. Neither NVD nor the official report mentions that the vulnerability has been exploited in actual attacks.

The reason behind document metadata exposure
The flaw lay in the way SiYuan implemented access control. The two paths verified whether the document the reader requested was published, but did not individually filter each document that appeared in its references. Thus, the published page acted as an entry point for data from unpublished notes.
The official security bulletin, codenamed GHSA-v758-8w88-pfr2, was published on September 20, 2026. The CVEFeed entry with the identifier CVE-2026-105205 appeared on October 4. Therefore, the CVE number is newer than the original technical disclosure; it does not mean that the issue was discovered or fixed on that day. The date refers to the posting, not the onset of the vulnerability or the release of the fix.
For a brief update on SiYuan, version 3.8.5 of the project, released on September 22, includes a general mention of fixes for “some security vulnerabilities.” The security notice names 3.8.5 as the fixed version, while the newer 3.8.6 was released on September 29 and also includes general security fixes.
See also: SiYuan Publishing Codes: Critical Control Point Void Allows Brute-Force

What administrators should check
Administrators should verify which version each installation is running and upgrade to at least 3.8.5, where the official security bulletin places the fix. 3.8.6 is a newer version listed on the project page. The update needs to be applied to every node or replica of the installation, not just the master service.
After upgrading, it is useful to review public pages and publishing settings, especially when private notes and public documents coexist on the same system. Administrators can test access as a reader or from an incognito browser window to confirm that private document metadata is no longer visible from published pages.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CVE-2026-66012: critical vulnerability in SiYuan exposes MCP tools and workspace files
The SecNews technical team notes that this vulnerability was related to information about documents, not their content. However, the appearance of identifiers and a large number of references can reveal the structure of a private collection of notes. Installing the patched version remains the main measure for those using the publishing function.
