<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 01:42:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352774</link>
      <description>EUVD-2026-352774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352774</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73606</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73606</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73606</guid>
    </item>
    <item>
      <title>GHSA-vg99-7gj7-2fr5 — SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protec…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vg99-7gj7-2fr5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`/api/block/getRefIDs` filters its results for reader roles through a helper that checks only the visibility tiers. The password tier is not checked, because the helper does not receive the request context and therefore cannot evaluate the publish auth cookie. A reader who has not entered a document&amp;#39;s publish password learns that the document references a given block.&lt;/p&gt;
&lt;p&gt;A function ten lines away in the same file does perform the full check, on the same input type.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Route,** identical at `eef105683` (`kernel/api/router.go:235`) and dev `a7ae96ce` (`:245`):&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/block/getRefIDs&amp;#34;, model.CheckAuth, getRefIDs)
```&lt;/p&gt;
&lt;p&gt;No `CheckReadonly`, no `CheckAdminRole`.&lt;/p&gt;
&lt;p&gt;**The filter chain.** `getRefIDs` (`kernel/api/block.go:631`) checks `isEncryptedNotebookDeniedForPublish`, calls `model.GetBlockRefsInBox`, then for read-only roles:&lt;/p&gt;
&lt;p&gt;```go
publishIgnore := model.GetInvisiblePublishAccess(publishAccess)
refDefs, originalRefBlockIDs = model.FilterRefDefsByPublishIgnore(publishIgnore, refDefs)
```&lt;/p&gt;
&lt;p&gt;`FilterRefDefsByPublishIgnore` (`kernel/model/publish_access.go:1324`) collects the reference and definition identifiers, resolves their block trees, and delegates the decision to `FilterBlockTreesByPublishIgnore` (`:1314`), whose entire body is:&lt;/p&gt;
&lt;p&gt;```go
for id, bt := range bts {
    if CheckPathAccessableByPublishIgnore(bt.BoxID, bt.Path, publishIgnore) {
        ret[id] = bt
    }
}
```&lt;/p&gt;
&lt;p&gt;Inside that helper, `CheckPublishAuthCookie`, `GetPath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`/api/block/getRefIDs` filters its results for reader roles through a helper that checks only the visibility tiers. The password tier is not checked, because the helper does not receive the request context and therefore cannot evaluate the publish auth cookie. A reader who has not entered a document&amp;#39;s publish password learns that the document references a given block.&lt;/p&gt;
&lt;p&gt;A function ten lines away in the same file does perform the full check, on the same input type.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Route,** identical at `eef105683` (`kernel/api/router.go:235`) and dev `a7ae96ce` (`:245`):&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/block/getRefIDs&amp;#34;, model.CheckAuth, getRefIDs)
```&lt;/p&gt;
&lt;p&gt;No `CheckReadonly`, no `CheckAdminRole`.&lt;/p&gt;
&lt;p&gt;**The filter chain.** `getRefIDs` (`kernel/api/block.go:631`) checks `isEncryptedNotebookDeniedForPublish`, calls `model.GetBlockRefsInBox`, then for read-only roles:&lt;/p&gt;
&lt;p&gt;```go
publishIgnore := model.GetInvisiblePublishAccess(publishAccess)
refDefs, originalRefBlockIDs = model.FilterRefDefsByPublishIgnore(publishIgnore, refDefs)
```&lt;/p&gt;
&lt;p&gt;`FilterRefDefsByPublishIgnore` (`kernel/model/publish_access.go:1324`) collects the reference and definition identifiers, resolves their block trees, and delegates the decision to `FilterBlockTreesByPublishIgnore` (`:1314`), whose entire body is:&lt;/p&gt;
&lt;p&gt;```go
for id, bt := range bts {
    if CheckPathAccessableByPublishIgnore(bt.BoxID, bt.Path, publishIgnore) {
        ret[id] = bt
    }
}
```&lt;/p&gt;
&lt;p&gt;Inside that helper, `CheckPublishAuthCookie`, `GetPath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vg99-7gj7-2fr5</guid>
    </item>
  </channel>
</rss>
