---
id: CVE-2026-72798
aliases:
  - GHSA-mfrj-v65r-979c
title: >-
  SiYuan: Publish-access filter on renderAttributeView leaves related-database
  content unfiltered and fails open on non-block first columns
summary: >-
  SiYuan: Publish-access filter on renderAttributeView leaves related-database
  content unfiltered and fails open on non-block first columns
severity: high
cvss: 8.6
cwe:
  - CWE-862
vendor: siyuan-note
product: github.com/siyuan-note/siyuan/kernel
ecosystem: go
affected:
  - github.com/siyuan-note/siyuan/kernel < 0.0.0-20260724121519-426991d155c0
patched:
  - github.com/siyuan-note/siyuan/kernel 0.0.0-20260724121519-426991d155c0
published: '2026-09-04'
updated: '2026-09-04'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-mfrj-v65r-979c'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mfrj-v65r-979c
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72798'
  - url: >-
      https://github.com/siyuan-note/siyuan/commit/426991d155c0c7c3a9e71badd6761eddfa8aad5b
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-renderattributeview
  - url: 'https://github.com/advisories/GHSA-mfrj-v65r-979c'
tags:
  - ghsa
  - go
epss: 0.00434
epssPercentile: 0.35009
ingestedAt: '2026-09-04T21:27:58.312Z'
---

## Overview

**CVE:** This vulnerability corresponds to [CVE-2026-72798](https://nvd.nist.gov/vuln/detail/CVE-2026-72798).

### Summary

`renderAttributeView` correctly applies the reader publish-access filter, but the filter's row-accessibility decision is keyed solely to the row's **first cell**, and it never inspects the remaining cells' values. Relation and Rollup cells carry mirrored content from a *different* database, so a row belonging to a published database can hand an anonymous reader the contents of a related database whose host document is hidden, publish-forbidden, or password-protected. Separately, when the first column is not a block value the accessibility check is skipped entirely and the row is returned unchecked.

### Note:

This is distinct from the previously reported password-tier omission in the same function that concerns the row's own primary block, whereas these two defects concern (a) other cells' related-database content, which no row-level check covers and (b) rows where the first cell is not a block at all. A fix to the row-drop condition alone would close neither.

### Details

`renderAttributeView` applies the filter (`kernel/api/av.go:68`):
```go
retDataMap["view"] = model.FilterViewByPublishAccess(c, publishAccess, retDataMap["view"].(av.Viewable))
```

Inside `FilterViewByPublishAccess` (`kernel/model/publish_access.go`):
```go
if row.Cells[0].Value.Block != nil {
    bt = treenode.GetBlockTree(row.Cells[0].Value.Block.ID)
}
if bt != nil {
    if !CheckPathAccessableByPublishIgnore(bt.BoxID, bt.Path, publishIgnore) {
        row = nil   // drop
    }
}
// every other cell in the row is returned as-is
```

**(a) Relation and Rollup cells leak the related database.** These value types carry mirrored content, not just references:
```go
type ValueRelation struct { BlockIDs []string; Contents []*Value }
type ValueRollup   struct { Contents []*Value }
```
The render pipeline populates them from a different attribute view e.g. `kernel/model/attribute_view.go:2731`:
```go
v.GroupVal.Relation.Contents = []*av.Value{ relationDestAv.GetBlockValue(groupValue) }
```
`relationDestAv` is a separate database that may live in a hidden, publish-forbidden, or password-protected document. When a published database's row survives the filter (because its column-0 document is public), its Relation and Rollup columns return the related, non-published database's content block text, titles, and mirrored column values. `FilterViewByPublishAccess` performs no publish-access evaluation on `Relation.Contents` or `Rollup.Contents`.

**(b) Fail-open when column 0 is not a block.** `bt` is assigned only when `row.Cells[0].Value.Block != nil`. If the first column is a non-block type (Relation, Text, …) or the row is detached, `bt` remains `nil`, the `if bt != nil` guard is skipped, and the row is returned with no accessibility check at all. Column order is user-reorderable, so any database whose first column is not the document block bypasses row filtering entirely.

Verified at `origin/master` (`eef105683`).

### Proof of Concept

Precondition: publish mode enabled (default port 6808); anonymous when `Publish.Auth.Enable` is `false`. Two databases: **DB-A** hosted in a published document, **DB-B** hosted in a publish-forbidden or password-protected document, with a Relation column in DB-A pointing at DB-B and containing a distinctive marker value.

**(a) Related-database content disclosure:**
```
POST http://127.0.0.1:6808/api/av/renderAttributeView
{"id":"<DB_A_AV_ID>"}
```
Rows of DB-A are returned (correctly, since its host document is public), and their Relation/Rollup cell `Contents` include DB-B's block text and mirrored column values, despite DB-B's host document being excluded from publishing.

**(b) Fail-open row:**
Reorder DB-A so its first column is a non-block type (or use a detached row), mark its host document publish-forbidden, and request the same endpoint the row is returned without any accessibility evaluation.

*Verification status:* both defects are confirmed by code inspection at `origin/master`. A live demonstration requires a build from HEAD with two linked databases; available on request.

### Impact

An anonymous reader (publish mode with auth disabled) or any publish `RoleReader` can read content from databases whose host documents are hidden, publish-forbidden, or password-protected, by requesting a *published* database that relates to them. Because relation graphs are commonly used to link a public index to private detail records, this exposes exactly the data the publish boundary is meant to withhold. The fail-open path additionally returns rows with no accessibility check whenever the first column is not a block value, which is a user-controlled layout property. Confidentiality-only.

### Suggested fix

In `FilterViewByPublishAccess`:
1. For each retained row, evaluate every `Relation.Contents` and `Rollup.Contents` entry against `CheckBlockIdAccessableByPublishAccess` (including the publish-password tier) and drop or mask entries that fail.
2. Fail closed: when `row.Cells[0]` has no accessible block (`Value.Block == nil` or `bt == nil`), drop the row rather than returning it unchecked.

## Affected packages

- `github.com/siyuan-note/siyuan/kernel < 0.0.0-20260724121519-426991d155c0`

## Remediation

Upgrade to a patched release:

- `github.com/siyuan-note/siyuan/kernel 0.0.0-20260724121519-426991d155c0`
