highCVSS 7.5Vulnerability

CVE-2026-74904

Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`) anywhere in the function body. 17 of 28 candidate endpoints have none. Cross-checked against the file's own sibling functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which correctly implement the check, confirming this is a real, uneven gap rather than a deliberate design choice for the whole file. ### Summary 17 handlers in `kernel/api/block.go`, all gated only by `model.CheckAuth` with no admin-role requirement, return block content-derived text, structural metadata, or existence information for any block ID supplied, with no access check anywhere in the handler or, for the ones checked in detail, the model functions they call. This is CWE-862 (Missing Authorization), the same class as the companion advisories from this review round, found in a different file via a systematic bulk check rather than manual inspection of each function individually. ### Details Confirmed via automated extraction of every function body between `func NAME(c *gin.Context) {` and the next such declaration, then searching each for any of `IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`, or `PublishAccess`. The following contain none of these, at all: | Endpoint | What it discloses | |---|---| | `getRefText` | The block's actual reference-display text, derived from its content, for any ID (`kernel/api/block.go:564`) | | `getBlockBreadcrumb` | The block's breadcrumb/title path (`:?`) | | `getBlockDefIDsByRefText` | Which block IDs a given reference text resolves to | | `getRefIDsByFileAnnotationID` | Block IDs referencing a given PDF/file annotation | | `getBlockIndex` / `getBlocksIndexes` | A block's position/index within its document | | `getTreeStat` | Structural statistics for a document tree | | `getBlocksWordCount` / `g

Properties

severity
high
summary
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
epss_score
0.00504
cvss_score
7.5
retrieved_at
2026-10-03T18:15:53+00:00
ghsa_published
2026-10-02T23:05:33Z
source_url
https://github.com/advisories/GHSA-4vpg-gwqq-w44c
ghsa_updated
2026-10-02T23:05:34Z
ghsa_id
GHSA-4vpg-gwqq-w44c
last_source
FIRST EPSS
cve_id
CVE-2026-74904
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
false
epss_percentile
0.40919

Related Entities (6)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]go/github.com/siyuan-note/siyuan/kernel

AFFECTS (1)

→[Software]go/github.com/siyuan-note/siyuan/kernel

HAS_WEAKNESS (2)

→[Weakness]Observable Response Discrepancy
→[Weakness]Missing Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph