Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
GHSA-v598-7627-g9fx
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-vpjw-wf5h-cgpq. This link is maintained to preserve external references.
Original Description
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.
Ready to move
Start Securing
Free, no credit card | First findings in minutes