<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:09:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292036</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292036</link>
      <description>EUVD-2026-292036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292036</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40259</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40259</link>
      <description>&lt;p&gt;SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service RoleReader tokens. The handler passes a caller-controlled id directly to a model function that unconditionally deletes the corresponding attribute view file from the workspace without verifying that the caller has write privileges or that the target attribute view is actually unused. An authenticated publish-service reader can permanently delete arbitrary attribute view definitions by extracting publicly exposed data-av-id values from published content, causing breakage of database views and workspace rendering until manually restored. This issue has been fixed in version 3.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service RoleReader tokens. The handler passes a caller-controlled id directly to a model function that unconditionally deletes the corresponding attribute view file from the workspace without verifying that the caller has write privileges or that the target attribute view is actually unused. An authenticated publish-service reader can permanently delete arbitrary attribute view definitions by extracting publicly exposed data-av-id values from published content, causing breakage of database views and workspace rendering until manually restored. This issue has been fixed in version 3.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40259</guid>
    </item>
    <item>
      <title>GHSA-7m5h-w69j-qggg — SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7m5h-w69j-qggg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An authenticated publish-service reader can invoke `/api/av/removeUnusedAttributeView` and cause persistent deletion of arbitrary attribute view (`AV`) definition files from the workspace.&lt;/p&gt;
&lt;p&gt;The route is protected only by generic `CheckAuth`, which accepts publish `RoleReader` requests. The handler forwards a caller-controlled `id` directly into a model function that deletes `data/storage/av/&amp;lt;id&amp;gt;.json` without verifying either:&lt;/p&gt;
&lt;p&gt;- that the caller is allowed to perform write/destructive actions; or
- that the target AV is actually unused.&lt;/p&gt;
&lt;p&gt;This is a persistent integrity and availability issue reachable from the publish surface.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;### 1. Publish users are issued a `RoleReader` JWT&lt;/p&gt;
&lt;p&gt;- [kernel/model/auth.go](/root/audit/siyuan/kernel/model/auth.go#L105)&lt;/p&gt;
&lt;p&gt;```go
ClaimsKeyRole: RoleReader,
```&lt;/p&gt;
&lt;p&gt;### 2. The publish reverse proxy forwards that token upstream&lt;/p&gt;
&lt;p&gt;- [kernel/server/proxy/publish.go](/root/audit/siyuan/kernel/server/proxy/publish.go#L131)
- [kernel/server/proxy/publish.go](/root/audit/siyuan/kernel/server/proxy/publish.go#L186)&lt;/p&gt;
&lt;p&gt;### 3. `CheckAuth` accepts `RoleReader`&lt;/p&gt;
&lt;p&gt;- [kernel/model/session.go](/root/audit/siyuan/kernel/model/session.go#L201)&lt;/p&gt;
&lt;p&gt;```go
if role := GetGinContextRole(c); IsValidRole(role, []Role{
    RoleAdministrator,
    RoleEditor,
    RoleReader,
}) {
    c.Next()
    return
}
```&lt;/p&gt;
&lt;p&gt;### 4. The route is exposed with `CheckAuth` only&lt;/p&gt;
&lt;p&gt;- [kernel/api/router.go](/root/audit/siyuan/kernel/api/router.go#L507)&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An authenticated publish-service reader can invoke `/api/av/removeUnusedAttributeView` and cause persistent deletion of arbitrary attribute view (`AV`) definition files from the workspace.&lt;/p&gt;
&lt;p&gt;The route is protected only by generic `CheckAuth`, which accepts publish `RoleReader` requests. The handler forwards a caller-controlled `id` directly into a model function that deletes `data/storage/av/&amp;lt;id&amp;gt;.json` without verifying either:&lt;/p&gt;
&lt;p&gt;- that the caller is allowed to perform write/destructive actions; or
- that the target AV is actually unused.&lt;/p&gt;
&lt;p&gt;This is a persistent integrity and availability issue reachable from the publish surface.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;### 1. Publish users are issued a `RoleReader` JWT&lt;/p&gt;
&lt;p&gt;- [kernel/model/auth.go](/root/audit/siyuan/kernel/model/auth.go#L105)&lt;/p&gt;
&lt;p&gt;```go
ClaimsKeyRole: RoleReader,
```&lt;/p&gt;
&lt;p&gt;### 2. The publish reverse proxy forwards that token upstream&lt;/p&gt;
&lt;p&gt;- [kernel/server/proxy/publish.go](/root/audit/siyuan/kernel/server/proxy/publish.go#L131)
- [kernel/server/proxy/publish.go](/root/audit/siyuan/kernel/server/proxy/publish.go#L186)&lt;/p&gt;
&lt;p&gt;### 3. `CheckAuth` accepts `RoleReader`&lt;/p&gt;
&lt;p&gt;- [kernel/model/session.go](/root/audit/siyuan/kernel/model/session.go#L201)&lt;/p&gt;
&lt;p&gt;```go
if role := GetGinContextRole(c); IsValidRole(role, []Role{
    RoleAdministrator,
    RoleEditor,
    RoleReader,
}) {
    c.Next()
    return
}
```&lt;/p&gt;
&lt;p&gt;### 4. The route is exposed with `CheckAuth` only&lt;/p&gt;
&lt;p&gt;- [kernel/api/router.go](/root/audit/siyuan/kernel/api/router.go#L507)&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7m5h-w69j-qggg</guid>
    </item>
  </channel>
</rss>
