HIGH 7.5 GitHub
CVE-2026-74904
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
Same CWE-862 family, found via an automated bulk sweep of every
`/api/block/*` handler in `kernel/api/block.go` for the presence of any
access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`,
`GetPublishAccess`) anywhere in the function body. 17 of 28 candidate
endpoints have none. Cross-checked against the file's own sibling
functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which
correctly implement the check, confirming this is a real, uneven gap
rather than a d
Affected Products
- go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260804015139-bd067a4fe9b2
References
- https://github.com/advisories/GHSA-4vpg-gwqq-w44c
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4vpg-gwqq-w44c
- https://nvd.nist.gov/vuln/detail/CVE-2026-74904
- https://github.com/siyuan-note/siyuan/commit/bd067a4fe9b208c0858d8d9dc6220dc8affc403e
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260804015139-bd067a4fe9b2.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.