GHSA-9cqf-hhrq-7v45
### Scope note This endpoint does not exist in v3.7.3 or on master. It was introduced on the development branch by commit `9b8e8956f` on 2026-07-27 and is present on the current development head. No released stable version is affected. ### Summary `/api/av/getAttributeViewSearchTarget` is registered with `CheckAuth` only and performs no authorization of any kind. Given a database identifier and a keyword, it searches that database's rows and returns matching content, regardless of whether the caller may see the database, the rows, or the notebook holding them. Commit `64c26e74b` on 2026-07-26 closed a reader-reachable gap on `getAttributeViewFieldViews` by adding `CheckReadonly` at router line 536. `9b8e8956f`, the following day, registered this endpoint at line 535 without it. The new route returns more than the one that was just closed: row content rather than field-visibility metadata. ### Details **Route.** `kernel/api/router.go:535` on the development branch: ```go ginServer.Handle("POST", "/api/av/getAttributeViewSearchTarget", model.CheckAuth, getAttributeViewSearchTarget) ``` No `CheckReadonly`, no `CheckAdminRole`. **Handler.** `kernel/api/av.go` parses its arguments and calls `model.GetAttributeViewSearchTarget(id, keywords)`. `IsReadOnlyRoleContext`, `publishAccess` and any encrypted-notebook check are all absent. The sink is `kernel/model/attribute_view_render.go:69`. **The adjacent routes make the omission stark.** Lines 533 to 541 all handle the same data class: | Line | Route | Guard | |---|---|---| | 534 | `getAttributeViewKeys` | `CheckAuth`, filters in-body for readers | | 535 | `getAttributeViewSearchTarget` | `CheckAuth`, nothing | | 536 | `getAttributeViewFieldViews` | `CheckAuth`, `CheckReadonly` | | 540 | `searchAttributeView` | `CheckAuth`, `CheckReadonly` | | 541 | `getAttributeView` | `CheckAuth`, `CheckReadonly` | The guard at 536 is the one added by `64c26e74b`. The new route sits directly above it without one. **Why this is
Properties
- severity
- high
- summary
- SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
- cvss_score
- 8.6
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T16:24:38Z
- source_url
- https://github.com/advisories/GHSA-9cqf-hhrq-7v45
- ghsa_updated
- 2026-10-01T16:24:39Z
- ghsa_id
- GHSA-9cqf-hhrq-7v45
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-9cqf-hhrq-7v45
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph