<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:25:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352690</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352690</link>
      <description>EUVD-2026-352690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352690</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68586</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68586</link>
      <description>&lt;p&gt;SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document&amp;#39;s ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document&amp;#39;s ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68586</guid>
    </item>
    <item>
      <title>GHSA-36v8-mpjm-8j5r — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendere…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36v8-mpjm-8j5r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-68586](https://nvd.nist.gov/vuln/detail/CVE-2026-68586).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The backlink API splits into list endpoints (which documents reference a block) and content endpoints (the rendered text of those referencing blocks). The list endpoints apply a publish-access filter, the content endpoints do not. As a result, `/api/ref/getBacklinkDoc` and `/api/ref/getBackmentionDoc` return the rendered DOM of blocks belonging to a publish-forbidden document to an anonymous reader, with no access check.&lt;/p&gt;
&lt;p&gt;Both content endpoints are gated by `CheckAuth` only, reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The asymmetry between the list and content sides is the tell that this is an oversight, not intended behavior:&lt;/p&gt;
&lt;p&gt;| Endpoint | Returns | Publish-access filter | Route |
|---|---|---|---|
| `getBacklink` | list (`*Path`) | `FilterPathsByPublishAccess` - present | `CheckAuth` |
| `getBacklink2` | list (`*Path`) | `FilterPathsByPublishAccess` - present | `CheckAuth` |
| `getBacklinkDoc` | rendered DOM | none | `CheckAuth` |
| `getBackmentionDoc` | rendered DOM | none | `CheckAuth` |&lt;/p&gt;
&lt;p&gt;`model/backlink.go` contains no publish-access reference anywhere, and `Backlink.DOM` is the rendered HTML of the referencing blocks. `getBacklinkDoc(defID, refTreeID)` returns the rendered content of blocks in `refTreeID` - including a publish-forbidden, publish-disabled, or password…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-68586](https://nvd.nist.gov/vuln/detail/CVE-2026-68586).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The backlink API splits into list endpoints (which documents reference a block) and content endpoints (the rendered text of those referencing blocks). The list endpoints apply a publish-access filter, the content endpoints do not. As a result, `/api/ref/getBacklinkDoc` and `/api/ref/getBackmentionDoc` return the rendered DOM of blocks belonging to a publish-forbidden document to an anonymous reader, with no access check.&lt;/p&gt;
&lt;p&gt;Both content endpoints are gated by `CheckAuth` only, reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The asymmetry between the list and content sides is the tell that this is an oversight, not intended behavior:&lt;/p&gt;
&lt;p&gt;| Endpoint | Returns | Publish-access filter | Route |
|---|---|---|---|
| `getBacklink` | list (`*Path`) | `FilterPathsByPublishAccess` - present | `CheckAuth` |
| `getBacklink2` | list (`*Path`) | `FilterPathsByPublishAccess` - present | `CheckAuth` |
| `getBacklinkDoc` | rendered DOM | none | `CheckAuth` |
| `getBackmentionDoc` | rendered DOM | none | `CheckAuth` |&lt;/p&gt;
&lt;p&gt;`model/backlink.go` contains no publish-access reference anywhere, and `Backlink.DOM` is the rendered HTML of the referencing blocks. `getBacklinkDoc(defID, refTreeID)` returns the rendered content of blocks in `refTreeID` - including a publish-forbidden, publish-disabled, or password…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36v8-mpjm-8j5r</guid>
    </item>
  </channel>
</rss>
