<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:42:01.129075+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352928</id>
    <title>EUVD-2026-352928</title>
    <updated>2026-10-08T08:42:01.185414+00:00</updated>
    <content>EUVD-2026-352928</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73609</id>
    <title>fkie_cve-2026-73609</title>
    <updated>2026-10-08T08:42:01.185452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j4ph-9xwf-wcj4</id>
    <title>GHSA-j4ph-9xwf-wcj4 — SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access fi…</title>
    <updated>2026-10-08T08:42:01.185484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>### Summary</p>
<p>`/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label in the workspace. An anonymous reader in publish mode receives the author's complete bookmark vocabulary, regardless of whether the bookmarked blocks live in published, hidden, password-protected or forbidden documents.</p>
<p>The adjacent endpoint that returns bookmarks with their blocks does filter, and does so in a way that makes the intended rule explicit: it drops a label entirely when no accessible block carries it.</p>
<p>### Details</p>
<p>**Route.** `kernel/api/router.go:297` on master, `:300` on the development branch:</p>
<p>```go
ginServer.Handle("POST", "/api/attr/getBookmarkLabels", model.CheckAuth, getBookmarkLabels)
```</p>
<p>No `CheckAdminRole`, no `CheckReadonly`. Reachable by the publish `RoleReader` token and anonymously when `Publish.Auth.Enable` is `false`.</p>
<p>**The handler** (`kernel/api/attr.go`) is a single line:</p>
<p>```go
ret.Data = model.BookmarkLabels()
```</p>
<p>which reaches `kernel/model/bookmark.go:184` and then `sql.QueryBookmarkLabels()` at `kernel/sql/block_query.go:315`:</p>
<p>```go
sqlStmt := "SELECT * FROM blocks WHERE ial LIKE ?"   // "%bookmark=%"
// collect distinct ialAttr(block.IAL, "bookmark") into a set, sort, return
```</p>
<p>There is no notebook scoping, no path scoping, no publish-access check and no filter function anywhere on the path. Every block in the workspace…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j4ph-9xwf-wcj4"/>
  </entry>
</feed>
