THREAT OPS › Threat News › [GHSA] GHSA-vpjw-wf5h-cgpq (high) — SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
[GHSA] GHSA-vpjw-wf5h-cgpq (high) — SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
GHSA-vpjw-wf5h-cgpq Severity: high CVE: CVE-2026-72804
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
**CVE:** This vulnerability corresponds to CVE-2026-72804.
### Summary
`getGraph` and `getLocalGraph` filter reader sessions against the *visibility* tier o
Indicators of compromise
- CVE-2026-72804cve
- http://127.0.0.1:6808/api/graph/getLocalGraphurl
- http://127.0.0.1:6808/api/graph/getGraphurl
Original source: https://github.com/advisories/GHSA-vpjw-wf5h-cgpq