Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password
GHSA-f68g-4xv8-2g75
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-mp7r-57w4-5qm3. This link is maintained to preserve external references.
Original Description
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.
Ready to move
Start Securing
Free, no credit card | First findings in minutes