CVE-2026-85174
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
- Published Sep 3, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available