MEDIUM 5.8 GitHub

CVE-2026-72788

SiYuan discloses an administrator's open documents and search terms to anonymous readers

### Summary `/api/system/getConf` serves `Conf.UILayout` to publish readers after passing it through `FilterConfByPublishIgnore`, whose only function is to filter that layout. The layout is written exclusively by `setUILayout`, which is administrator-gated, so what readers receive is the administrator's own live workspace state, re-saved on every tab open, close and focus change. The filter that is supposed to protect it, `filterLayoutItemByPublishIgnore`, has four separate defects. Together t

Affected Products

References

Published: 2026-10-01 · Source: GitHub · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-01 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.