<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:51:18.169983+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352689</id>
    <title>EUVD-2026-352689</title>
    <updated>2026-10-06T15:51:18.290787+00:00</updated>
    <content>EUVD-2026-352689</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352689"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68585</id>
    <title>fkie_cve-2026-68585</title>
    <updated>2026-10-06T15:51:18.290846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pm3w-vxp9-ccwc</id>
    <title>GHSA-pm3w-vxp9-ccwc — SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info f…</title>
    <updated>2026-10-06T15:51:18.290900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>**CVE:** This vulnerability corresponds to [CVE-2026-68585](https://nvd.nist.gov/vuln/detail/CVE-2026-68585).</p>
<p>### Summary</p>
<p>The `/api/block/getBlockInfo` endpoint returns document root metadata including the document title (`rootTitle`) for a block in a publish-forbidden document, with no publish-access check. Its sibling `/api/block/getDocInfo` applies the publish-access filter, `getBlockInfo` does not. Both are gated by `CheckAuth` only, so `getBlockInfo` is reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`.</p>
<p>### Details</p>
<p>The list/info side of this API is filtered while the block-info twin is not the asymmetry indicates an oversight rather than intended behavior:</p>
<p>| Endpoint | Returns | Publish-access filter | Route |
|---|---|---|---|
| `getDocInfo` | document info/metadata | present | `CheckAuth` |
| `getBlockInfo` | `box, path, rootID, rootTitle, rootChildID, rootIcon` | none | `CheckAuth` |</p>
<p>`getBlockInfo` takes a caller-supplied block ID, validates only its format, and returns the containing document's root metadata including `rootTitle` (the document title) with no `IsReadOnlyRoleContext` / publish-access check. Because `getDocInfo` performs the filtering for equivalent data, the boundary is clearly meant to apply here; `getBlockInfo` omits it.</p>
<p>### Proof of Concept</p>
<p>Reproduced on a local instance (SiYuan running locally, publish mode enabled on port 6808, publish Basic Auth disabled). Setup: a publish-forb…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pm3w-vxp9-ccwc"/>
  </entry>
</feed>
