HIGH 7.5 GitHub

CVE-2026-74904

SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers

Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`) anywhere in the function body. 17 of 28 candidate endpoints have none. Cross-checked against the file's own sibling functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which correctly implement the check, confirming this is a real, uneven gap rather than a d

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-03
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260804015139-bd067a4fe9b2.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.