<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 16:25:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352695</link>
      <description>EUVD-2026-352695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352695</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69086</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69086</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69086</guid>
    </item>
    <item>
      <title>GHSA-7hm9-v7vf-7g4w — SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope att…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hm9-v7vf-7g4w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-69086](https://nvd.nist.gov/vuln/detail/CVE-2026-69086).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Four attribute-view read endpoints build a filesystem path from a caller-controlled `id`/`avID` and read it without confining the result to the attribute-view storage directory (`DataDir/storage/av/`). On the load (file-exists) code path there is no boundary check, so an `avID` containing `../` segments escapes `storage/av/` and causes the kernel to read a `.json` file elsewhere in the workspace.&lt;/p&gt;
&lt;p&gt;The endpoints require only `CheckAuth`, which the publish service&amp;#39;s `RoleReader` token satisfies; when `Publish.Auth.Enable` is `false` the publish proxy uses the anonymous account, making the surface reachable with no credentials.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Affected endpoints (all gated by `CheckAuth` only, no `CheckAdminRole`):&lt;/p&gt;
&lt;p&gt;- `POST /api/av/renderAttributeView` &amp;amp;nbsp;→ `arg[&amp;#34;id&amp;#34;]`
- `POST /api/av/getAttributeViewKeysByID` → `arg[&amp;#34;avID&amp;#34;]`
- `POST /api/av/getAttributeViewKeys` &amp;amp;nbsp;→ `arg[&amp;#34;id&amp;#34;]`
- `POST /api/av/getCurrentAttrViewImages` → `arg[&amp;#34;id&amp;#34;]`&lt;/p&gt;
&lt;p&gt;In `model.RenderAttributeView` (`model/attribute_view_render.go`), the only identifier guard `ast.IsNodeIDPattern(avID)` sits **inside** the `if !filelock.IsExist(existPath)` (create) branch:&lt;/p&gt;
&lt;p&gt;```go
existPath = GetAttributeViewDataPath(avID)      // path built from avID, no check
if !filelock.IsExist(existPath) {               // NOT-EXIST / CREATE branch
    if !createIfNotExist {
        return // NotFound
    }
    if…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-69086](https://nvd.nist.gov/vuln/detail/CVE-2026-69086).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Four attribute-view read endpoints build a filesystem path from a caller-controlled `id`/`avID` and read it without confining the result to the attribute-view storage directory (`DataDir/storage/av/`). On the load (file-exists) code path there is no boundary check, so an `avID` containing `../` segments escapes `storage/av/` and causes the kernel to read a `.json` file elsewhere in the workspace.&lt;/p&gt;
&lt;p&gt;The endpoints require only `CheckAuth`, which the publish service&amp;#39;s `RoleReader` token satisfies; when `Publish.Auth.Enable` is `false` the publish proxy uses the anonymous account, making the surface reachable with no credentials.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Affected endpoints (all gated by `CheckAuth` only, no `CheckAdminRole`):&lt;/p&gt;
&lt;p&gt;- `POST /api/av/renderAttributeView` &amp;amp;nbsp;→ `arg[&amp;#34;id&amp;#34;]`
- `POST /api/av/getAttributeViewKeysByID` → `arg[&amp;#34;avID&amp;#34;]`
- `POST /api/av/getAttributeViewKeys` &amp;amp;nbsp;→ `arg[&amp;#34;id&amp;#34;]`
- `POST /api/av/getCurrentAttrViewImages` → `arg[&amp;#34;id&amp;#34;]`&lt;/p&gt;
&lt;p&gt;In `model.RenderAttributeView` (`model/attribute_view_render.go`), the only identifier guard `ast.IsNodeIDPattern(avID)` sits **inside** the `if !filelock.IsExist(existPath)` (create) branch:&lt;/p&gt;
&lt;p&gt;```go
existPath = GetAttributeViewDataPath(avID)      // path built from avID, no check
if !filelock.IsExist(existPath) {               // NOT-EXIST / CREATE branch
    if !createIfNotExist {
        return // NotFound
    }
    if…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hm9-v7vf-7g4w</guid>
    </item>
  </channel>
</rss>
