CVE-2026-85579 | SiYuan-Note SiYuan up to 3.8.1 Undo Log undoState root ID information disclosure
A vulnerability was found in SiYuan-Note SiYuan up to 3.8.1 and classified as problematic. This affects an unknown part of the file /api/transactions/undoState of the component Undo Log. Executing a manipulation of the argument root ID can lead to information disclosure.
This vulnerability is tracked as CVE-2026-85579. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More