CVE-2026-74904
Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`) anywhere in the function body. 17 of 28 candidate endpoints have none. Cross-checked against the file's own sibling functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which correctly implement the check, confirming this is a real, uneven gap rather than a deliberate design choice for the whole file. ### Summary 17 handlers in `kernel/api/block.go`, all gated only by `model.CheckAuth` with no admin-role requirement, return block content-derived text, structural metadata, or existence information for any block ID supplied, with no access check anywhere in the handler or, for the ones checked in detail, the model functions they call. This is CWE-862 (Missing Authorization), the same class as the companion advisories from this review round, found in a different file via a systematic bulk check rather than manual inspection of each function individually. ### Details Confirmed via automated extraction of every function body between `func NAME(c *gin.Context) {` and the next such declaration, then searching each for any of `IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`, or `PublishAccess`. The following contain none of these, at all: | Endpoint | What it discloses | |---|---| | `getRefText` | The block's actual reference-display text, derived from its content, for any ID (`kernel/api/block.go:564`) | | `getBlockBreadcrumb` | The block's breadcrumb/title path (`:?`) | | `getBlockDefIDsByRefText` | Which block IDs a given reference text resolves to | | `getRefIDsByFileAnnotationID` | Block IDs referencing a given PDF/file annotation | | `getBlockIndex` / `getBlocksIndexes` | A block's position/index within its document | | `getTreeStat` | Structural statistics for a document tree | | `getBlocksWordCount` / `g
Properties
- severity
- high
- summary
- SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
- epss_score
- 0.00504
- cvss_score
- 7.5
- retrieved_at
- 2026-10-03T18:15:53+00:00
- ghsa_published
- 2026-10-02T23:05:33Z
- source_url
- https://github.com/advisories/GHSA-4vpg-gwqq-w44c
- ghsa_updated
- 2026-10-02T23:05:34Z
- ghsa_id
- GHSA-4vpg-gwqq-w44c
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-74904
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.40919
Related Entities (6)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph