GHSA-fxmw-rv85-5hwhMediumCVSS 5.8

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the...

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-wide block IDs without publish scoping, enabling attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents.

🔗 References (4)