Skip to content

x/vulndb: potential Go vuln in github.com/siyuan-note/siyuan/kernel: GHSA-f68g-4xv8-2g75 #6422

Description

@GoVulnBot

Advisory GHSA-f68g-4xv8-2g75 references a vulnerability in the following Go modules:

Module
github.com/siyuan-note/siyuan/kernel

Description:

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-mp7r-57w4-5qm3. This link is maintained to preserve external references.

Original Description

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/siyuan-note/siyuan/kernel
      vulnerable_at: 0.0.0-20260830025221-44a6c212a994
summary: |-
    Duplicate Advisory: Tag labels from password-protected documents are returned to
    readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
ghsas:
    - GHSA-f68g-4xv8-2g75
references:
    - advisory: https://github.com/advisories/GHSA-f68g-4xv8-2g75
    - web: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mp7r-57w4-5qm3
    - web: https://nvd.nist.gov/vuln/detail/CVE-2026-72792
    - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-tag-api
source:
    id: GHSA-f68g-4xv8-2g75
    created: 2026-09-04T22:01:52.50695677Z
review_status: UNREVIEWED

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions