GO-2026-6632None▾ SunlitSiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel >= 0.0.0-20260726161145-9b8e8956f997, < 0.0.0-20260812083335-251596fc0de2Upgrade to a patched release:
github.com/siyuan-note/siyuan/kernel 0.0.0-20260812083335-251596fc0de2Connected by shared product, vendor, weakness, or advisory.
GHSA-9cqf-hhrq-7v45High· 8.6SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class …
CVE-2026-74802Low· 0.0SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` by…
CVE-2026-74904High· 7.5SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mod…
CVE-2026-73609Medium· 5.8SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
CVE-2026-73606Medium· 5.8SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents refe…
CVE-2026-73607Medium· 5.8SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no a…