{"id":"CVE-2026-72806","aliases":["GHSA-6mcf-g667-w3qv","GO-2026-6388"],"title":"SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…","summary":"SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","vendor":"siyuan-note","product":"github.com/siyuan-note/siyuan/kernel","ecosystem":"go","affected":["github.com/siyuan-note/siyuan/kernel < 0.0.0-20260723040913-768427f20f13"],"patched":["github.com/siyuan-note/siyuan/kernel 0.0.0-20260723040913-768427f20f13"],"published":"2026-09-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:25:48.380557211Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-6mcf-g667-w3qv","references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6mcf-g667-w3qv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72806"},{"url":"https://github.com/siyuan-note/siyuan/commit/768427f20f13bbd8dc4effa8aa4e1d09a7741bf4"},{"url":"https://github.com/siyuan-note/siyuan"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-attribute-view"},{"url":"https://github.com/advisories/GHSA-6mcf-g667-w3qv"}],"tags":["osv","go","ghsa"],"epss":0.00307,"epssPercentile":0.23674,"cwe":["CWE-862"],"ingestedAt":"2026-09-03T23:10:02.337Z","slug":"CVE-2026-72806","body":"## Overview\n\n**CVE:** This vulnerability corresponds to [CVE-2026-72806](https://nvd.nist.gov/vuln/detail/CVE-2026-72806).\n\n### Summary\n\n`FilterViewByPublishAccess`, the filter `renderAttributeView` applies for Reader sessions drops rows using only the hidden/forbidden check and never checks the publish password. Its three sibling filters all check both tiers. As a result, a publish `RoleReader` (or the anonymous account when `Publish.Auth.Enable` is `false`) who has not entered a document's password still receives every database/attribute-view row bound to that password-protected document, the primary cell (title/ID) and all column values.\n\n### Details\n\n`FilterViewByPublishAccess` (`model/publish_access.go:290`) drops rows on the hidden/forbidden tier only:\n```go\n// Table (line 311), Gallery (348), Kanban (385), all identical:\nif !CheckPathAccessableByPublishIgnore(bt.BoxID, bt.Path, publishIgnore) {\n    row = nil   // hidden/forbidden dropped, but password NEVER checked\n}\n```\n\nThe three sibling filters all check both the hidden/forbidden tier and the password tier (`password == \"\" || CheckPublishAuthCookie(...)`):\n- `FilterBlockAttributeViewKeysByPublishAccess` (line 412)\n- `FilterBlockInfoByPublishAccess` (line 457)\n- `FilterContentByPublishAccess` (line 474)\n\nSo the password (protected) tier is enforced everywhere except this AV/database-view filter. Table layout masks nothing; Gallery and Kanban mask only the cover, keeping the card and its non-cover values. Reachable via `renderAttributeView`, `getAttributeViewKeys`, and `renderSnapshotAttributeView`, all `CheckAuth`-only.\n\n### Proof of Concept\n\nReproduced on a live instance (publish mode on 6808, anonymous Reader, no password cookie), against a password-protected document with a database/AV row.\n\n| Check | Path | Result |\n|---|---|---|\n| Control | `getDoc(secretDoc)` | 🔒 placeholder, body withheld password gate works normally |\n| Test | `renderAttributeView(AV)` | row leaked : `blockID=…rk7jofz`, title `secret-db-row` |\n| Differential (`disable=true`) | same filter | 0 rows : hidden tier correctly enforced |\n| Differential (password set) | same filter | 1 row : password tier bypassed |\n\nSame filter, same document, same Reader: the hidden tier drops the row, the password tier leaks it isolating the omission.\n\n### Impact\n\nAn anonymous/Reader publish user who has not supplied a protected document's password receives all attribute-view/database rows bound to that document titles, block IDs, and column values defeating the publish-password control for database views. Confidentiality-only. The hidden/forbidden tier is unaffected (correctly enforced).\n\n### Suggested fix\n\nAdd the password check to the drop condition in all three layout branches (Table, Gallery, Kanban), mirroring the sibling filters:\n```go\nif !CheckPathAccessableByPublishIgnore(...) ||\n   !(password == \"\" || CheckPublishAuthCookie(c, passwordID, password)) {\n    row = nil\n}\n```\n\n## Affected packages\n\n- `github.com/siyuan-note/siyuan/kernel < 0.0.0-20260723040913-768427f20f13`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/siyuan-note/siyuan/kernel 0.0.0-20260723040913-768427f20f13`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}