THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vpjw-wf5h-cgpq (high) — SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

[GHSA] GHSA-vpjw-wf5h-cgpq (high) — SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

highgithub_advisoriesPublished 2026-09-03

GHSA-vpjw-wf5h-cgpq Severity: high CVE: CVE-2026-72804

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

**CVE:** This vulnerability corresponds to CVE-2026-72804.

### Summary

`getGraph` and `getLocalGraph` filter reader sessions against the *visibility* tier o

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vpjw-wf5h-cgpq