<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:19:46.733741+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352695</id>
    <title>EUVD-2026-352695</title>
    <updated>2026-10-05T22:19:46.789379+00:00</updated>
    <content>EUVD-2026-352695</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69086</id>
    <title>fkie_cve-2026-69086</title>
    <updated>2026-10-05T22:19:46.789450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7hm9-v7vf-7g4w</id>
    <title>GHSA-7hm9-v7vf-7g4w — SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope att…</title>
    <updated>2026-10-05T22:19:46.789483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>**CVE:** This vulnerability corresponds to [CVE-2026-69086](https://nvd.nist.gov/vuln/detail/CVE-2026-69086).</p>
<p>### Summary</p>
<p>Four attribute-view read endpoints build a filesystem path from a caller-controlled `id`/`avID` and read it without confining the result to the attribute-view storage directory (`DataDir/storage/av/`). On the load (file-exists) code path there is no boundary check, so an `avID` containing `../` segments escapes `storage/av/` and causes the kernel to read a `.json` file elsewhere in the workspace.</p>
<p>The endpoints require only `CheckAuth`, which the publish service's `RoleReader` token satisfies; when `Publish.Auth.Enable` is `false` the publish proxy uses the anonymous account, making the surface reachable with no credentials.</p>
<p>### Details</p>
<p>Affected endpoints (all gated by `CheckAuth` only, no `CheckAdminRole`):</p>
<p>- `POST /api/av/renderAttributeView` &amp;nbsp;→ `arg["id"]`
- `POST /api/av/getAttributeViewKeysByID` → `arg["avID"]`
- `POST /api/av/getAttributeViewKeys` &amp;nbsp;→ `arg["id"]`
- `POST /api/av/getCurrentAttrViewImages` → `arg["id"]`</p>
<p>In `model.RenderAttributeView` (`model/attribute_view_render.go`), the only identifier guard `ast.IsNodeIDPattern(avID)` sits **inside** the `if !filelock.IsExist(existPath)` (create) branch:</p>
<p>```go
existPath = GetAttributeViewDataPath(avID)      // path built from avID, no check
if !filelock.IsExist(existPath) {               // NOT-EXIST / CREATE branch
    if !createIfNotExist {
        return // NotFound
    }
    if…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7hm9-v7vf-7g4w"/>
  </entry>
</feed>
