THREAT OPS › Threat News › [GHSA] GHSA-h6w7-xxcf-w2mq (high) — SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
[GHSA] GHSA-h6w7-xxcf-w2mq (high) — SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
GHSA-h6w7-xxcf-w2mq Severity: high CVE: CVE-2026-72795
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
**CVE:** This vulnerability corresponds to CVE-2026-72795.
### Summary
`/api/block/getBlockDOMWithEmbed` and `/api/block/
Indicators of compromise
- CVE-2026-72795cve
- http://127.0.0.1:6808/api/block/getBlockDOMWithEmbedurl
- http://127.0.0.1:6808/api/search/getEmbedBlockurl
- http://127.0.0.1:6808/api/block/getBlockDOMsWithEmbedurl
Original source: https://github.com/advisories/GHSA-h6w7-xxcf-w2mq