SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
id: GO-ID-PENDING
modules:
- module: github.com/siyuan-note/siyuan/kernel
vulnerable_at: 0.0.0-20260830025221-44a6c212a994
summary: |-
Duplicate Advisory: Embedded (transclusion) block content is returned without
publish-access filtering, leaking private and password-protected document
content to anonymous readers in github.com/siyuan-note/siyuan/kernel
ghsas:
- GHSA-cjwm-9h7g-pcr9
references:
- advisory: https://github.com/advisories/GHSA-cjwm-9h7g-pcr9
- web: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h6w7-xxcf-w2mq
- web: https://nvd.nist.gov/vuln/detail/CVE-2026-72795
- web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-embed-block
source:
id: GHSA-cjwm-9h7g-pcr9
created: 2026-09-04T22:01:51.340561981Z
review_status: UNREVIEWED
Advisory GHSA-cjwm-9h7g-pcr9 references a vulnerability in the following Go modules:
Description:
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-h6w7-xxcf-w2mq. This link is maintained to preserve external references.
Original Description
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.