THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h6w7-xxcf-w2mq (high) — SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

[GHSA] GHSA-h6w7-xxcf-w2mq (high) — SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

highgithub_advisoriesPublished 2026-09-04

GHSA-h6w7-xxcf-w2mq Severity: high CVE: CVE-2026-72795

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

**CVE:** This vulnerability corresponds to CVE-2026-72795.

### Summary

`/api/block/getBlockDOMWithEmbed` and `/api/block/

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h6w7-xxcf-w2mq