GHSA-75xh-mp4f-f2rfCritical· 8.6▾ MidnightDuplicate Advisory: SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9cqf-hhrq-7v45. This link is maintained to preserve external references.
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs no authorization checks (no CheckReadonly, no publish-access or encrypted-notebook gating). Given a database identifier taken from a published page and a keyword, an anonymous reader can query the endpoint to retrieve matching database row content, including rows that publish filters (FilterAttributeViewByPublishAccess) would otherwise withhold. No released stable version is affected.
github.com/siyuan-note/siyuan/kernel >= 0.0.0-20260726161145-9b8e8956f997, < 0.0.0-20260812083335-251596fc0de2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-9cqf-hhrq-7v45High· 8.6SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
CVE-2026-73609Medium· 5.8SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
GHSA-7v6h-j59w-8qfpMedium· 5.8Duplicate Advisory: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
CVE-2026-73607Medium· 5.8SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
GHSA-v372-phq5-6mx6Medium· 5.8Duplicate Advisory: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
CVE-2026-73605Medium· 5.8SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem