GHSA-7v6h-j59w-8qfpMedium· 5.8▾ SunlitDuplicate Advisory: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-j4ph-9xwf-wcj4. This link is maintained to preserve external references.
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.
github.com/siyuan-note/siyuan/kernel < 3.7.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73609Medium· 5.8SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
GHSA-9cqf-hhrq-7v45High· 8.6SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
GHSA-75xh-mp4f-f2rfCritical· 8.6Duplicate Advisory: SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
CVE-2026-73607Medium· 5.8SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
GHSA-v372-phq5-6mx6Medium· 5.8Duplicate Advisory: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
CVE-2026-73605Medium· 5.8SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem