THREAT OPS › Threat News › [GHSA] GHSA-36v8-mpjm-8j5r (high) — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
[GHSA] GHSA-36v8-mpjm-8j5r (high) — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
GHSA-36v8-mpjm-8j5r Severity: high CVE: CVE-2026-68586
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
**CVE:** This vulnerability corresponds to CVE-2026-68586.
### Summary
The backlink API splits into li
Indicators of compromise
- CVE-2026-68586cve
- http://127.0.0.1:6806/api/filetree/setPublishAccessurl
- http://127.0.0.1:6808/api/ref/getBacklink2url
- http://127.0.0.1:6808/api/ref/getBacklinkDocurl
Original source: https://github.com/advisories/GHSA-36v8-mpjm-8j5r