SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.
id: GO-ID-PENDING
modules:
- module: github.com/siyuan-note/siyuan/kernel
vulnerable_at: 0.0.0-20260830025221-44a6c212a994
summary: |-
Duplicate Advisory: Tag labels from password-protected documents are returned to
readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
ghsas:
- GHSA-f68g-4xv8-2g75
references:
- advisory: https://github.com/advisories/GHSA-f68g-4xv8-2g75
- web: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mp7r-57w4-5qm3
- web: https://nvd.nist.gov/vuln/detail/CVE-2026-72792
- web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-tag-api
source:
id: GHSA-f68g-4xv8-2g75
created: 2026-09-04T22:01:52.50695677Z
review_status: UNREVIEWED
Advisory GHSA-f68g-4xv8-2g75 references a vulnerability in the following Go modules:
Description:
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-mp7r-57w4-5qm3. This link is maintained to preserve external references.
Original Description
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.