Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Kernel: SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

0
High
Published: 09/03/2026 (09/03/2026, 21:22:42 UTC)
Source: GCVE Database
Product: github.com/siyuan-note/siyuan/kernel

Description

**CVE:** This vulnerability corresponds to [CVE-2026-68584](https://nvd.nist.gov/vuln/detail/CVE-2026-68584). ### Summary SiYuan's publish mode defines a "protected" access level: a document that is publicly listed but requires a password to read (per the product's own UI help text, protected = "Publicly visible, requires password to access"). The password is enforced on the primary content path (`getDoc`, via `FilterContentByPublishAccess`). Several other content-returning endpoints `getHeadingChildrenDOM`, `getHeadingDeleteTransaction`/`getHeadingLevelTransaction`/ `getHeadingInsertTransaction`, and `getBacklinkDoc`/`getBackmentionDoc` return rendered block DOM with **no password check at all**. Combined with reader-reachable endpoints that leak a protected document's internal block IDs, an anonymous reader can retrieve the full body of a password-protected document without the password. This has been reproduced end-to-end on a live instance. ### Details **The password control and where it is enforced.** Publish access has five levels encoded in `visible`/`password`/`disable`: public, protected (password), hidden, private (password), forbidden. `getDoc` correctly enforces the password for protected/private documents via `FilterContentByPublishAccess`. The bug is that other content endpoints do not. **Content endpoints with no password check (all `CheckAuth`-only):** - `getHeadingChildrenDOM` returns rendered DOM of a heading subtree. - `getHeadingDeleteTransaction`/`getHeadingLevelTransaction`/`getHeadingInsertTransaction` return rendered heading DOM in the computed transaction payload (no mutation occurs on this path). - `getBacklinkDoc`/`getBackmentionDoc` return rendered DOM of referencing blocks. None of these invokes the publish-password check that `getDoc` applies. Each converts a block ID into full rendered content regardless of the containing document's protected/password status. **The ID-leak that removes the precondition.** A protected document is, by design, publicly listed (`listDocsByPath` filters on `visible`, and protected documents are visible), so an anonymous reader obtains the document's root ID. The document's internal block/heading IDs are then obtainable from reader-reachable endpoints notably the `searchEmbedBlock` endpoint (reported separately), whose post-query filter `FilterEmbedBlocksByPublishAccess` **replaces the content string but retains the block ID**. So the "filtered" search still yields the protected document's internal heading IDs. (Other reader-reachable endpoints also leak block IDs, the vulnerability does not depend on any single ID source.) **The chain, reproduced on a live instance.** Against a real protected document (password set), an anonymous reader on port 6808 with no token and no password: 1. `getDoc(protectedDoc)` → returns the password-required placeholder (correctly blocked). 2. `searchEmbedBlock` with a statement selecting heading blocks for the document's root ID → returns the heading IDs (content filtered, IDs retained). 3. `getHeadingChildrenDOM(headingId)` → returns the full rendered body of the protected document, including its protected content. The password gate that step 1 enforces is entirely bypassed by step 3. ### Proof of Concept Reproduced on a local instance (SiYuan running locally, publish mode enabled on port 6808, publish Basic Auth disabled). Setup: a document marked "protected" with password, whose body contains the unique marker `TOP_SECRET_CRITICAL_123`. **1. Confirm the password gate blocks the primary path (anonymous, port 6808):** ``` POST http://127.0.0.1:6808/api/filetree/getDoc {"id":"PROTECTED_DOC"} ``` Returns the password-required placeholder correctly blocked. **2. Leak the protected document's heading ID (anonymous, port 6808):** ``` POST http://127.0.0.1:6808/api/search/searchEmbedBlock {"stmt":"SELECT * FROM blocks WHERE root_id='PROTECTED_DOC' AND type='h'"} ``` Returns heading blocks with their IDs; the content field is filtered but the block ID is retained. **3. Retrieve the protected content without the password (anonymous, port 6808):** ``` POST http://127.0.0.1:6808/api/block/getHeadingChildrenDOM {"id":"HEADING_ID"} ``` Returns HTTP 200 with the rendered body of the protected document, including `TOP_SECRET_CRITICAL_123` retrieved with no token and no password. `getHeadingDeleteTransaction`/`getHeadingLevelTransaction`/`getHeadingInsertTransaction` and `getBacklinkDoc`/ `getBackmentionDoc` provide the same password-free content retrieval given a block ID from the protected document. ### Impact An anonymous reader (publish mode with auth disabled) or any publish `RoleReader` can read the full content of a password-protected published document without the password, defeating the "protected" access control the product documents as a password gate. The core defect is that these content-returning endpoints perform no publish-password check; the ID-leak endpoints (multiple sources) supply the block ID

CVSS v3.1

Score 8.6high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected software

Goghsa
github.com/siyuan-note/siyuan/kernel
Affected versions
<0.0.0-20260721020826-2d069dce84a2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-7j72-f6wg-cxw6
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["Go"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a9ad51dacd9273b49b689c5

Added to database: 09/04/2026, 14:26:37 UTC

Last updated: 09/04/2026, 17:16:10 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses