Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,060 advisories

Loading
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password Moderate
CVE-2026-72792 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password Moderate
GHSA-f68g-4xv8-2g75 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers Moderate
GHSA-cm9f-w4h4-7j85 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers Moderate
CVE-2026-72797 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: getEncryptedNotebookStatus discloses names and live unlock state of all encrypted notebooks to anonymous readers Moderate
GHSA-rchc-g58m-88jm was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers Moderate
CVE-2026-72799 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers Moderate
GHSA-v3v5-7j3j-cc6f was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) Moderate
GHSA-fxmw-rv85-5hwh was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
CVE-2026-72802 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
GHSA-72xp-24p9-7vpf was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents Moderate
GHSA-h4w7-mgq4-wg6x was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents Moderate
GHSA-89hf-xcx5-r9r6 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) Moderate
CVE-2026-72808 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) Moderate
GHSA-mhcc-g592-267j was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root Moderate
CVE-2026-61625 was published for github.com/VictoriaMetrics/VictoriaMetrics (Go) Sep 3, 2026
sondt99 Credited to sondt99, dungNHVhust, arkid15r, and makasim dungNHVhust dungNHVhust
arkid15r arkid15r makasim makasim
ProTip! Advisories are also available from the GraphQL API