检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5FHR-F75J-8WR9 CVE-2026-72800 | SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 07:04 | 2026-09-04 07:04 |
| GHSA-8X84-R2FF-H8PQ CVE-2026-72801 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/siyuan-note/siyuan/kernel |
| 已审查 |
| 2026-09-04 07:02 |
| 2026-09-04 07:02 |
| GHSA-JV8V-XQ2H-657V CVE-2026-72802 | SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 07:00 | 2026-09-04 07:00 |
| GHSA-QVQ9-HQ6P-V378 CVE-2026-72803 | SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:58 | 2026-09-04 06:58 |
| GHSA-VPJW-WF5H-CGPQ CVE-2026-72804 | SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:52 | 2026-09-04 06:52 |
| GHSA-67X2-MQ63-V9VM CVE-2026-72805 | SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:52 | 2026-09-04 06:52 |
| GHSA-6MCF-G667-W3QV CVE-2026-72806 | SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:50 | 2026-09-04 06:50 |
| GHSA-X67C-8PWR-M8G3 CVE-2026-72807 | SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:49 | 2026-09-04 06:49 |
| GHSA-V7PH-R5R6-4JCJ CVE-2026-72808 | SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:48 | 2026-09-04 06:48 |
| GHSA-3MP7-4RH5-JRV9 CVE-2026-72809 | SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:34 | 2026-09-04 06:34 |
| GHSA-MW8R-MW84-88V2 CVE-2026-72810 | SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:30 | 2026-09-04 06:30 |
| GHSA-Q2VG-7QGX-X5FC CVE-2026-72811 | SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:27 | 2026-09-04 06:27 |
| GHSA-WGWX-479J-23VQ CVE-2026-72812 | SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 06:23 | 2026-09-04 06:23 |
| GHSA-7J72-F6WG-CXW6 | SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:22 | 2026-09-04 05:22 |
| GHSA-PM3W-VXP9-CCWC CVE-2026-68585 | SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:22 | 2026-09-04 05:22 |
| GHSA-36V8-MPJM-8J5R CVE-2026-68586 | SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:21 | 2026-09-04 05:21 |
| GHSA-69MH-GVH4-8GP7 CVE-2026-68587 | SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:19 | 2026-09-04 05:19 |
| GHSA-FPH3-GHQ9-VW66 CVE-2026-69083 | SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 05:01 | 2026-09-04 05:01 |
| GHSA-82X6-Q7MM-W9CF CVE-2026-77465 | toml-node: Uncontrolled Recursion | 高危 | npmtoml | 已审查 | 2026-09-04 04:56 | 2026-09-04 04:56 |
| GHSA-V5MP-JGW5-2X6J CVE-2026-63376 | toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization | 高危 | npmtoml | 已审查 | 2026-09-04 04:55 | 2026-09-04 04:55 |
| GHSA-7HM9-V7VF-7G4W CVE-2026-69086 | SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 04:34 | 2026-09-04 04:34 |
| GHSA-6983-JFQ8-485W CVE-2026-56811 | Phoenix: Unbounded channel joins per transport enables DoS over few connections | 高危 | Hexphoenix | 已审查 | 2026-09-04 04:33 | 2026-09-04 04:33 |
| GHSA-63MC-HW7G-86RR CVE-2026-56812 | Phoenix: Presence keys colliding with `Object.prototype` members break existence checks | 中危 | Hexphoenix | 已审查 | 2026-09-04 04:30 | 2026-09-04 04:30 |
| GHSA-528H-PC64-C93X CVE-2026-71429 | stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS) | 中危 | npmstream-json | 已审查 | 2026-09-04 04:27 | 2026-09-04 04:27 |
| GHSA-VH22-H7HF-WWW7 CVE-2026-69084 | SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 04:19 | 2026-09-04 04:19 |