highCVSS 8.6Vulnerability

GHSA-9cqf-hhrq-7v45

### Scope note This endpoint does not exist in v3.7.3 or on master. It was introduced on the development branch by commit `9b8e8956f` on 2026-07-27 and is present on the current development head. No released stable version is affected. ### Summary `/api/av/getAttributeViewSearchTarget` is registered with `CheckAuth` only and performs no authorization of any kind. Given a database identifier and a keyword, it searches that database's rows and returns matching content, regardless of whether the caller may see the database, the rows, or the notebook holding them. Commit `64c26e74b` on 2026-07-26 closed a reader-reachable gap on `getAttributeViewFieldViews` by adding `CheckReadonly` at router line 536. `9b8e8956f`, the following day, registered this endpoint at line 535 without it. The new route returns more than the one that was just closed: row content rather than field-visibility metadata. ### Details **Route.** `kernel/api/router.go:535` on the development branch: ```go ginServer.Handle("POST", "/api/av/getAttributeViewSearchTarget", model.CheckAuth, getAttributeViewSearchTarget) ``` No `CheckReadonly`, no `CheckAdminRole`. **Handler.** `kernel/api/av.go` parses its arguments and calls `model.GetAttributeViewSearchTarget(id, keywords)`. `IsReadOnlyRoleContext`, `publishAccess` and any encrypted-notebook check are all absent. The sink is `kernel/model/attribute_view_render.go:69`. **The adjacent routes make the omission stark.** Lines 533 to 541 all handle the same data class: | Line | Route | Guard | |---|---|---| | 534 | `getAttributeViewKeys` | `CheckAuth`, filters in-body for readers | | 535 | `getAttributeViewSearchTarget` | `CheckAuth`, nothing | | 536 | `getAttributeViewFieldViews` | `CheckAuth`, `CheckReadonly` | | 540 | `searchAttributeView` | `CheckAuth`, `CheckReadonly` | | 541 | `getAttributeView` | `CheckAuth`, `CheckReadonly` | The guard at 536 is the one added by `64c26e74b`. The new route sits directly above it without one. **Why this is

Properties

severity
high
summary
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
cvss_score
8.6
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T16:24:38Z
source_url
https://github.com/advisories/GHSA-9cqf-hhrq-7v45
ghsa_updated
2026-10-01T16:24:39Z
ghsa_id
GHSA-9cqf-hhrq-7v45
last_source
GitHub Advisory Database
cve_id
GHSA-9cqf-hhrq-7v45
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/github.com/siyuan-note/siyuan/kernel

AFFECTS (1)

→[Software]go/github.com/siyuan-note/siyuan/kernel

HAS_WEAKNESS (1)

→[Weakness]Missing Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9cqf-hhrq-7v45 (CVSS 8.6) — Ninja Signal Threat Intelligence | Ninja Signal