<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 13:53:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352928</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352928</link>
      <description>EUVD-2026-352928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352928</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73609</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73609</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73609</guid>
    </item>
    <item>
      <title>GHSA-j4ph-9xwf-wcj4 — SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access fi…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j4ph-9xwf-wcj4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label in the workspace. An anonymous reader in publish mode receives the author&amp;#39;s complete bookmark vocabulary, regardless of whether the bookmarked blocks live in published, hidden, password-protected or forbidden documents.&lt;/p&gt;
&lt;p&gt;The adjacent endpoint that returns bookmarks with their blocks does filter, and does so in a way that makes the intended rule explicit: it drops a label entirely when no accessible block carries it.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Route.** `kernel/api/router.go:297` on master, `:300` on the development branch:&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/attr/getBookmarkLabels&amp;#34;, model.CheckAuth, getBookmarkLabels)
```&lt;/p&gt;
&lt;p&gt;No `CheckAdminRole`, no `CheckReadonly`. Reachable by the publish `RoleReader` token and anonymously when `Publish.Auth.Enable` is `false`.&lt;/p&gt;
&lt;p&gt;**The handler** (`kernel/api/attr.go`) is a single line:&lt;/p&gt;
&lt;p&gt;```go
ret.Data = model.BookmarkLabels()
```&lt;/p&gt;
&lt;p&gt;which reaches `kernel/model/bookmark.go:184` and then `sql.QueryBookmarkLabels()` at `kernel/sql/block_query.go:315`:&lt;/p&gt;
&lt;p&gt;```go
sqlStmt := &amp;#34;SELECT * FROM blocks WHERE ial LIKE ?&amp;#34;   // &amp;#34;%bookmark=%&amp;#34;
// collect distinct ialAttr(block.IAL, &amp;#34;bookmark&amp;#34;) into a set, sort, return
```&lt;/p&gt;
&lt;p&gt;There is no notebook scoping, no path scoping, no publish-access check and no filter function anywhere on the path. Every block in the workspace…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label in the workspace. An anonymous reader in publish mode receives the author&amp;#39;s complete bookmark vocabulary, regardless of whether the bookmarked blocks live in published, hidden, password-protected or forbidden documents.&lt;/p&gt;
&lt;p&gt;The adjacent endpoint that returns bookmarks with their blocks does filter, and does so in a way that makes the intended rule explicit: it drops a label entirely when no accessible block carries it.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Route.** `kernel/api/router.go:297` on master, `:300` on the development branch:&lt;/p&gt;
&lt;p&gt;```go
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/attr/getBookmarkLabels&amp;#34;, model.CheckAuth, getBookmarkLabels)
```&lt;/p&gt;
&lt;p&gt;No `CheckAdminRole`, no `CheckReadonly`. Reachable by the publish `RoleReader` token and anonymously when `Publish.Auth.Enable` is `false`.&lt;/p&gt;
&lt;p&gt;**The handler** (`kernel/api/attr.go`) is a single line:&lt;/p&gt;
&lt;p&gt;```go
ret.Data = model.BookmarkLabels()
```&lt;/p&gt;
&lt;p&gt;which reaches `kernel/model/bookmark.go:184` and then `sql.QueryBookmarkLabels()` at `kernel/sql/block_query.go:315`:&lt;/p&gt;
&lt;p&gt;```go
sqlStmt := &amp;#34;SELECT * FROM blocks WHERE ial LIKE ?&amp;#34;   // &amp;#34;%bookmark=%&amp;#34;
// collect distinct ialAttr(block.IAL, &amp;#34;bookmark&amp;#34;) into a set, sort, return
```&lt;/p&gt;
&lt;p&gt;There is no notebook scoping, no path scoping, no publish-access check and no filter function anywhere on the path. Every block in the workspace…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j4ph-9xwf-wcj4</guid>
    </item>
  </channel>
</rss>
