Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4w7-mgq4-wg6x

Опубликовано: 12 авг. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

Duplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-qvq9-hq6p-v378. This link is maintained to preserve external references.

Original Description

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.

Пакеты

Наименование

github.com/siyuan-note/siyuan/kernel

go
Затронутые версииВерсия исправления

<= 3.7.2

Отсутствует

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-862

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-862