{"id":"GHSA-69jp-f2p8-9vrg","title":"Duplicate Advisory: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers","summary":"Duplicate Advisory: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers","severity":"high","cvss":7.5,"cwe":["CWE-862"],"vendor":"siyuan-note","product":"github.com/siyuan-note/siyuan/kernel","ecosystem":"go","affected":["github.com/siyuan-note/siyuan/kernel < 3.7.4"],"published":"2026-08-18","updated":"2026-10-02","sourceUpdated":"2026-10-02T22:56:15Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-69jp-f2p8-9vrg","references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4vpg-gwqq-w44c"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74904"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-missing-authorization-via-block-api"},{"url":"https://github.com/advisories/GHSA-69jp-f2p8-9vrg"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-02T23:34:57.397Z","slug":"GHSA-69jp-f2p8-9vrg","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-4vpg-gwqq-w44c. This link is maintained to preserve external references.\n\n## Original Description\nSiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access filtering, allowing anonymous publish-mode readers to disclose private block content-derived text, structural metadata, and existence information for arbitrary block IDs across the workspace.\n\n## Affected packages\n\n- `github.com/siyuan-note/siyuan/kernel < 3.7.4`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}