GHSA-gq43-vcrh-6jw8Medium· 5.8▾ SunlitDuplicate Advisory: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-vg99-7gj7-2fr5. This link is maintained to preserve external references.
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.
github.com/siyuan-note/siyuan/kernel < 3.7.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73606Medium· 5.8SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
CVE-2026-72802Medium· 5.3SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
CVE-2026-73609Medium· 5.8SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
GHSA-7v6h-j59w-8qfpMedium· 5.8Duplicate Advisory: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
GHSA-9cqf-hhrq-7v45High· 8.6SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
GHSA-75xh-mp4f-f2rfCritical· 8.6Duplicate Advisory: SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route