<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:47:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278489</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278489</link>
      <description>EUVD-2026-278489</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278489</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34453</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34453</link>
      <description>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess(nil, ...). Because the filter treats a nil context as authorized, it skips the publish password check and returns bookmarked blocks from documents configured as Protected. As a result, anyone who can access the publish service can retrieve content from protected documents without providing the required password, as long as at least one block in the document is bookmarked. This issue has been patched in version 3.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess(nil, ...). Because the filter treats a nil context as authorized, it skips the publish password check and returns bookmarked blocks from documents configured as Protected. As a result, anyone who can access the publish service can retrieve content from protected documents without providing the required password, as long as at least one block in the document is bookmarked. This issue has been patched in version 3.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34453</guid>
    </item>
    <item>
      <title>GHSA-c77m-r996-jr3q — SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmark</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c77m-r996-jr3q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary
The publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, `/api/bookmark/getBookmark` filters bookmark results by calling `FilterBlocksByPublishAccess(nil, ...)`. Because the filter treats a `nil` context as authorized, it skips the publish password check and returns bookmarked blocks from documents configured as `Protected`. As a result, anyone who can access the publish service can retrieve content from protected documents without providing the required password, as long as at least one block in the document is bookmarked.&lt;/p&gt;
&lt;p&gt;### Details
The issue is caused by an authorization bypass in the bookmark API path used by the publish service.&lt;/p&gt;
&lt;p&gt;In `kernel/api/bookmark.go`, `getBookmark` checks whether the current request is in a read-only role and then filters bookmarks for publish access. However, it passes `nil` as the request context:
```go
if model.IsReadOnlyRoleContext(c) {
    publishAccess := model.GetPublishAccess()
    tempBookmarks := &amp;amp;model.Bookmarks{}
    for _, bookmark := range *bookmarks {
        bookmark.Blocks = model.FilterBlocksByPublishAccess(nil, publishAccess, bookmark.Blocks)
```
In `kernel/model/publish_access.go`, `FilterBlocksByPublishAccess` allows access when `c == nil`:
```go
if CheckPathAccessableByPublishIgnore(block.Box, block.Path, publishIgnore) &amp;amp;&amp;amp;
   (c == nil || password == &amp;#34;&amp;#34; || CheckPublishAuthCookie(c, passwordID, password)) {
    ret = append(ret, block…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary
The publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, `/api/bookmark/getBookmark` filters bookmark results by calling `FilterBlocksByPublishAccess(nil, ...)`. Because the filter treats a `nil` context as authorized, it skips the publish password check and returns bookmarked blocks from documents configured as `Protected`. As a result, anyone who can access the publish service can retrieve content from protected documents without providing the required password, as long as at least one block in the document is bookmarked.&lt;/p&gt;
&lt;p&gt;### Details
The issue is caused by an authorization bypass in the bookmark API path used by the publish service.&lt;/p&gt;
&lt;p&gt;In `kernel/api/bookmark.go`, `getBookmark` checks whether the current request is in a read-only role and then filters bookmarks for publish access. However, it passes `nil` as the request context:
```go
if model.IsReadOnlyRoleContext(c) {
    publishAccess := model.GetPublishAccess()
    tempBookmarks := &amp;amp;model.Bookmarks{}
    for _, bookmark := range *bookmarks {
        bookmark.Blocks = model.FilterBlocksByPublishAccess(nil, publishAccess, bookmark.Blocks)
```
In `kernel/model/publish_access.go`, `FilterBlocksByPublishAccess` allows access when `c == nil`:
```go
if CheckPathAccessableByPublishIgnore(block.Box, block.Path, publishIgnore) &amp;amp;&amp;amp;
   (c == nil || password == &amp;#34;&amp;#34; || CheckPublishAuthCookie(c, passwordID, password)) {
    ret = append(ret, block…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c77m-r996-jr3q</guid>
    </item>
  </channel>
</rss>
