THREAT OPS › Threat News › [GHSA] GHSA-fgmr-7w36-9qfq (medium) — SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
[GHSA] GHSA-fgmr-7w36-9qfq (medium) — SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
GHSA-fgmr-7w36-9qfq Severity: medium CVE: CVE-2026-72796
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
**CVE:** This vulnerability corresponds to CVE-2026-72796.
### Summary
Several static-file routes in the server mux (`kernel/serv
Indicators of compromise
- CVE-2026-72796cve
- http://127.0.0.1:6808/templates/url
- http://127.0.0.1:6808/api/file/getFileurl
- http://127.0.0.1:6808/snippets/url
- http://127.0.0.1:6808/export/csv/url
Original source: https://github.com/advisories/GHSA-fgmr-7w36-9qfq