SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapp...
id: GO-ID-PENDING
modules:
- module: github.com/siyuan-note/siyuan/kernel
non_go_versions:
- introduced: TODO (earliest fixed "", vuln range "< 3.7.4")
vulnerable_at: 0.0.0-20260830025221-44a6c212a994
summary: |-
Duplicate Advisory: Missing publish-access filter on the HPath/path-resolution
endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel
ghsas:
- GHSA-v3v5-7j3j-cc6f
references:
- advisory: https://github.com/advisories/GHSA-v3v5-7j3j-cc6f
- web: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5w7r-f4cg-rqq7
- web: https://nvd.nist.gov/vuln/detail/CVE-2026-72799
- web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-path-resolution
source:
id: GHSA-v3v5-7j3j-cc6f
created: 2026-09-04T21:02:26.849853466Z
review_status: UNREVIEWED
Advisory GHSA-v3v5-7j3j-cc6f references a vulnerability in the following Go modules:
Description:
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-5w7r-f4cg-rqq7. This link is maintained to preserve external references.
Original Description
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapp...
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.