THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-36v8-mpjm-8j5r (high) — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

[GHSA] GHSA-36v8-mpjm-8j5r (high) — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

highgithub_advisoriesPublished 2026-09-03

GHSA-36v8-mpjm-8j5r Severity: high CVE: CVE-2026-68586

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

**CVE:** This vulnerability corresponds to CVE-2026-68586.

### Summary

The backlink API splits into li

Indicators of compromise

Original source: https://github.com/advisories/GHSA-36v8-mpjm-8j5r