<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 09:48:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352688</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352688</link>
      <description>EUVD-2026-352688</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352688</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68584</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68584</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68584</guid>
    </item>
    <item>
      <title>GHSA-7j72-f6wg-cxw6 — SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBackli…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j72-f6wg-cxw6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-68584](https://nvd.nist.gov/vuln/detail/CVE-2026-68584).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;SiYuan&amp;#39;s publish mode defines a &amp;#34;protected&amp;#34; access level: a document that is publicly listed but requires a password to read (per the product&amp;#39;s own UI help text, protected = &amp;#34;Publicly visible, requires password to access&amp;#34;). The password is enforced on the primary content path (`getDoc`, via `FilterContentByPublishAccess`).&lt;/p&gt;
&lt;p&gt;Several other content-returning endpoints `getHeadingChildrenDOM`, `getHeadingDeleteTransaction`/`getHeadingLevelTransaction`/ `getHeadingInsertTransaction`, and `getBacklinkDoc`/`getBackmentionDoc` return rendered block DOM with **no password check at all**. Combined with reader-reachable endpoints that leak a protected document&amp;#39;s internal block IDs, an anonymous reader can retrieve the full body of a password-protected document without the password. This has been reproduced end-to-end on a live instance.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**The password control and where it is enforced.** Publish access has five levels encoded in `visible`/`password`/`disable`: public, protected (password), hidden, private (password), forbidden. `getDoc` correctly enforces the password for protected/private documents via `FilterContentByPublishAccess`. The bug is that other content endpoints do not.&lt;/p&gt;
&lt;p&gt;**Content endpoints with no password check (all `CheckAuth`-only):**
- `getHeadingChildrenDOM` returns rendered DOM of a heading subtree.
- `getHeadingDeleteTransaction`/`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-68584](https://nvd.nist.gov/vuln/detail/CVE-2026-68584).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;SiYuan&amp;#39;s publish mode defines a &amp;#34;protected&amp;#34; access level: a document that is publicly listed but requires a password to read (per the product&amp;#39;s own UI help text, protected = &amp;#34;Publicly visible, requires password to access&amp;#34;). The password is enforced on the primary content path (`getDoc`, via `FilterContentByPublishAccess`).&lt;/p&gt;
&lt;p&gt;Several other content-returning endpoints `getHeadingChildrenDOM`, `getHeadingDeleteTransaction`/`getHeadingLevelTransaction`/ `getHeadingInsertTransaction`, and `getBacklinkDoc`/`getBackmentionDoc` return rendered block DOM with **no password check at all**. Combined with reader-reachable endpoints that leak a protected document&amp;#39;s internal block IDs, an anonymous reader can retrieve the full body of a password-protected document without the password. This has been reproduced end-to-end on a live instance.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**The password control and where it is enforced.** Publish access has five levels encoded in `visible`/`password`/`disable`: public, protected (password), hidden, private (password), forbidden. `getDoc` correctly enforces the password for protected/private documents via `FilterContentByPublishAccess`. The bug is that other content endpoints do not.&lt;/p&gt;
&lt;p&gt;**Content endpoints with no password check (all `CheckAuth`-only):**
- `getHeadingChildrenDOM` returns rendered DOM of a heading subtree.
- `getHeadingDeleteTransaction`/`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j72-f6wg-cxw6</guid>
    </item>
  </channel>
</rss>
