THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wgwx-479j-23vq (medium) — SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

[GHSA] GHSA-wgwx-479j-23vq (medium) — SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

highgithub_advisoriesPublished 2026-09-03

GHSA-wgwx-479j-23vq Severity: medium CVE: CVE-2026-72812

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

**CVE:** This vulnerability corresponds to CVE-2026-72812.

### Summary

The `/api/ref/refreshBacklink` endpoint is g

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wgwx-479j-23vq