<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:40:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352757</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352757</link>
      <description>EUVD-2026-352757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352757</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72802</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72802</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server&amp;#39;s absolute workspace path, disclosing the operating-system username and installation layout.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server&amp;#39;s absolute workspace path, disclosing the operating-system username and installation layout.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72802</guid>
    </item>
    <item>
      <title>GHSA-jv8v-xq2h-657v — SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jv8v-xq2h-657v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-72802](https://nvd.nist.gov/vuln/detail/CVE-2026-72802).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`POST /api/asset/resolveAssetPath` returns the resolved **absolute** filesystem path of an asset, unmodified. The route is `CheckAuth`-only, so it is reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`. An anonymous reader who knows any asset&amp;#39;s relative path trivially harvested from an `&amp;lt;img src=&amp;#34;assets/…&amp;#34;&amp;gt;` in any published document receives the server&amp;#39;s absolute workspace path, disclosing the operating-system username and the installation layout.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// kernel/api/asset.go: resolveAssetPath
p, err := model.GetAssetAbsPathInBox(path, &amp;#34;&amp;#34;)   // boxID=&amp;#34;&amp;#34; → absolute workspace path
...
ret.Data = p                                     // returned raw, no stripping
```&lt;/p&gt;
&lt;p&gt;`GetAssetAbsPathInBox(path, &amp;#34;&amp;#34;)` resolves under `util.DataDir` / `util.WorkspaceDir`, producing a full host path such as `C:\Users\&amp;lt;username&amp;gt;\SiYuan\data\assets\foo.png` or `/home/&amp;lt;user&amp;gt;/…`. The handler returns it directly with no redaction and no publish-scope check.&lt;/p&gt;
&lt;p&gt;**This is data the project already treats as sensitive.** `getConf` explicitly zeroes `System.WorkspaceDir`, `AppDir`, `ConfDir`, `DataDir`, and `HomeDir` when `util.IsBrowserRequest(c)`, a change made specifically to avoid leaking the username (issue #17410). `resolveAssetPath` performs no equivalent stripping, so it re-exposes precisely the values `getC…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-72802](https://nvd.nist.gov/vuln/detail/CVE-2026-72802).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`POST /api/asset/resolveAssetPath` returns the resolved **absolute** filesystem path of an asset, unmodified. The route is `CheckAuth`-only, so it is reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`. An anonymous reader who knows any asset&amp;#39;s relative path trivially harvested from an `&amp;lt;img src=&amp;#34;assets/…&amp;#34;&amp;gt;` in any published document receives the server&amp;#39;s absolute workspace path, disclosing the operating-system username and the installation layout.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// kernel/api/asset.go: resolveAssetPath
p, err := model.GetAssetAbsPathInBox(path, &amp;#34;&amp;#34;)   // boxID=&amp;#34;&amp;#34; → absolute workspace path
...
ret.Data = p                                     // returned raw, no stripping
```&lt;/p&gt;
&lt;p&gt;`GetAssetAbsPathInBox(path, &amp;#34;&amp;#34;)` resolves under `util.DataDir` / `util.WorkspaceDir`, producing a full host path such as `C:\Users\&amp;lt;username&amp;gt;\SiYuan\data\assets\foo.png` or `/home/&amp;lt;user&amp;gt;/…`. The handler returns it directly with no redaction and no publish-scope check.&lt;/p&gt;
&lt;p&gt;**This is data the project already treats as sensitive.** `getConf` explicitly zeroes `System.WorkspaceDir`, `AppDir`, `ConfDir`, `DataDir`, and `HomeDir` when `util.IsBrowserRequest(c)`, a change made specifically to avoid leaking the username (issue #17410). `resolveAssetPath` performs no equivalent stripping, so it re-exposes precisely the values `getC…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jv8v-xq2h-657v</guid>
    </item>
  </channel>
</rss>
