THREAT OPS › Threat News › [GHSA] GHSA-5w7r-f4cg-rqq7 (medium) — SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
[GHSA] GHSA-5w7r-f4cg-rqq7 (medium) — SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
GHSA-5w7r-f4cg-rqq7 Severity: medium CVE: CVE-2026-72799
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
**CVE:** This vulnerability corresponds to CVE-2026-72799.
### Summary
Five filetree endpoints resolve arbitrary document IDs and paths with no publish-ac
Indicators of compromise
- CVE-2026-72799cve
- http://127.0.0.1:6808/api/filetree/getFullHPathByIDurl
- http://127.0.0.1:6808/api/filetree/getPathByIDurl
- http://127.0.0.1:6808/api/filetree/getIDsByHPathurl
Original source: https://github.com/advisories/GHSA-5w7r-f4cg-rqq7