—— |
| 未审查 |
| 2026-09-04 08:31 |
| 2026-09-04 08:31 |
| GHSA-77PQ-762C-PM6C CVE-2026-62916 | 无摘要 | 严重 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-6X43-G54R-9P4X CVE-2026-18330 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-6HPQ-JHQF-P8V4 CVE-2026-18167 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-V5QJ-5Q4R-8FG9 CVE-2026-64196 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-PHQM-V98P-HR87 CVE-2026-64199 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-FGV7-3G4X-J73V CVE-2026-64198 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-9HX6-52XX-5GPH CVE-2026-64200 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-3JCP-WWXV-CMV9 CVE-2026-64195 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-28JJ-Q8CG-6FC9 CVE-2026-64197 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 08:31 | 2026-09-04 08:31 |
| GHSA-5FHR-F75J-8WR9 CVE-2026-72800 | SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 07:04 | 2026-09-04 07:04 |
| GHSA-8X84-R2FF-H8PQ CVE-2026-72801 | SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 07:02 | 2026-09-04 07:02 |
| GHSA-JV8V-XQ2H-657V CVE-2026-72802 | SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 07:00 | 2026-09-04 07:00 |
| GHSA-QVQ9-HQ6P-V378 CVE-2026-72803 | SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:58 | 2026-09-04 06:58 |
| GHSA-VPJW-WF5H-CGPQ CVE-2026-72804 | SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:52 | 2026-09-04 06:52 |
| GHSA-67X2-MQ63-V9VM CVE-2026-72805 | SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:52 | 2026-09-04 06:52 |
| GHSA-6MCF-G667-W3QV CVE-2026-72806 | SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:50 | 2026-09-04 06:50 |
| GHSA-X67C-8PWR-M8G3 CVE-2026-72807 | SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:49 | 2026-09-04 06:49 |
| GHSA-V7PH-R5R6-4JCJ CVE-2026-72808 | SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:48 | 2026-09-04 06:48 |
| GHSA-3MP7-4RH5-JRV9 CVE-2026-72809 | SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:34 | 2026-09-04 06:34 |
| GHSA-MW8R-MW84-88V2 CVE-2026-72810 | SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:30 | 2026-09-04 06:30 |
| GHSA-Q2VG-7QGX-X5FC CVE-2026-72811 | SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:27 | 2026-09-04 06:27 |
| GHSA-WGWX-479J-23VQ CVE-2026-72812 | SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:23 | 2026-09-04 06:23 |
| GHSA-WXM7-78M8-PMCH CVE-2026-85222 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 05:31 | 2026-09-04 05:31 |