THREAT OPS › Threat News › [GHSA] GHSA-69mh-gvh4-8gp7 (high) — SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
[GHSA] GHSA-69mh-gvh4-8gp7 (high) — SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
GHSA-69mh-gvh4-8gp7 Severity: high CVE: CVE-2026-68587
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
**CVE:** This vulnerability corresponds to CVE-2026-68587.
### Summary
Three "heading transaction" endpoints `/api/b
Indicators of compromise
- CVE-2026-68587cve
- http://127.0.0.1:6806/api/filetree/setPublishAccessurl
- http://127.0.0.1:6808/api/filetree/getDocurl
- http://127.0.0.1:6808/api/block/getHeadingDeleteTransactionurl
- http://127.0.0.1:6808/api/block/getHeadingLevelTransactionurl
- http://127.0.0.1:6808/api/block/getHeadingInsertTransactionurl
Original source: https://github.com/advisories/GHSA-69mh-gvh4-8gp7