—— |
| 未审查 |
| 2026-09-04 05:31 |
| 2026-09-04 05:31 |
| GHSA-8CVG-RXFW-4PF6 CVE-2026-85390 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-86W9-CPQP-85RV CVE-2026-85393 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-4QMW-8R9M-C656 CVE-2026-85028 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-3QF3-8W2G-RQMX CVE-2026-85394 | 无摘要 | 严重 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-3HVP-RQ7G-QF5W CVE-2026-85389 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-2MM8-PPW9-CQ8R CVE-2026-85395 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-23J5-GC8F-M7MC CVE-2026-82302 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-XVX8-CRX2-XJWV CVE-2026-78595 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-V6W2-J735-4M3P CVE-2026-82298 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-JM25-2Q7V-PHXV CVE-2026-15431 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-FCR2-G7H7-M264 CVE-2026-78596 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-6Q7W-4CG4-7827 CVE-2026-78593 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-59GF-XXWW-6GV7 CVE-2026-82299 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-3963-6MF6-92MQ CVE-2026-78583 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |
| GHSA-7J72-F6WG-CXW6 | SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:22 | 2026-09-04 05:22 |
| GHSA-PM3W-VXP9-CCWC CVE-2026-68585 | SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:22 | 2026-09-04 05:22 |
| GHSA-36V8-MPJM-8J5R CVE-2026-68586 | SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:21 | 2026-09-04 05:21 |
| GHSA-69MH-GVH4-8GP7 CVE-2026-68587 | SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:19 | 2026-09-04 05:19 |
| GHSA-FPH3-GHQ9-VW66 CVE-2026-69083 | SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:01 | 2026-09-04 05:01 |
| GHSA-82X6-Q7MM-W9CF CVE-2026-77465 | toml-node: Uncontrolled Recursion | 高危 | npmtoml | 已审查 | 2026-09-04 04:56 | 2026-09-04 04:56 |
| GHSA-V5MP-JGW5-2X6J CVE-2026-63376 | toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization | 高危 | npmtoml | 已审查 | 2026-09-04 04:55 | 2026-09-04 04:55 |
| GHSA-7HM9-V7VF-7G4W CVE-2026-69086 | SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 04:34 | 2026-09-04 04:34 |
| GHSA-6983-JFQ8-485W CVE-2026-56811 | Phoenix: Unbounded channel joins per transport enables DoS over few connections | 高危 | Hexphoenix | 已审查 | 2026-09-04 04:33 | 2026-09-04 04:33 |