THREAT OPS › Threat News › [GHSA] GHSA-wgwx-479j-23vq (medium) — SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
[GHSA] GHSA-wgwx-479j-23vq (medium) — SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
GHSA-wgwx-479j-23vq Severity: medium CVE: CVE-2026-72812
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
**CVE:** This vulnerability corresponds to CVE-2026-72812.
### Summary
The `/api/ref/refreshBacklink` endpoint is g
Indicators of compromise
- CVE-2026-72812cve
- http://127.0.0.1:6808/api/ref/refreshBacklinkurl
- http://127.0.0.1:6808/api/tag/renameTagurl
- http://127.0.0.1:6808/api/block/foldBlockurl
- http://127.0.0.1:6808/api/block/updateEmbedBlockurl
Original source: https://github.com/advisories/GHSA-wgwx-479j-23vq