THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-69mh-gvh4-8gp7 (high) — SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

[GHSA] GHSA-69mh-gvh4-8gp7 (high) — SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

highgithub_advisoriesPublished 2026-09-03

GHSA-69mh-gvh4-8gp7 Severity: high CVE: CVE-2026-68587

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

**CVE:** This vulnerability corresponds to CVE-2026-68587.

### Summary

Three "heading transaction" endpoints `/api/b

Indicators of compromise

Original source: https://github.com/advisories/GHSA-69mh-gvh4-8gp7