THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6mcf-g667-w3qv (medium) — SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

[GHSA] GHSA-6mcf-g667-w3qv (medium) — SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

medgithub_advisoriesPublished 2026-09-03

GHSA-6mcf-g667-w3qv Severity: medium CVE: CVE-2026-72806

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

**CVE:** This vulnerability corresponds to CVE-2026-72806.

### Summary

`FilterViewByPublishAccess`, the filter `renderA

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6mcf-g667-w3qv