Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ww86-c2qf-w8fw

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, bypassing read-only protections and enabling resource amplification attacks.

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, bypassing read-only protections and enabling resource amplification attacks.

EPSS

Процентиль: 20%
0.00275
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
5 дней назад

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, bypassing read-only protections and enabling resource amplification attacks.

EPSS

Процентиль: 20%
0.00275
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-862