MEDIUM 5.8 GitHub
CVE-2026-73606
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
### Summary
`/api/block/getRefIDs` filters its results for reader roles through a helper that checks only the visibility tiers. The password tier is not checked, because the helper does not receive the request context and therefore cannot evaluate the publish auth cookie. A reader who has not entered a document's publish password learns that the document references a given block.
A function ten lines away in the same file does perform the full check, on the same input type.
### Details
**Rou
Affected Products
- go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2
References
- https://github.com/advisories/GHSA-vg99-7gj7-2fr5
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5
- https://nvd.nist.gov/vuln/detail/CVE-2026-73606
- https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-01 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.