THREAT OPS › Threat News › [GHSA] GHSA-mp7r-57w4-5qm3 (medium) — SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
[GHSA] GHSA-mp7r-57w4-5qm3 (medium) — SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
GHSA-mp7r-57w4-5qm3 Severity: medium CVE: CVE-2026-72792
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
**CVE:** This vulnerability corresponds to CVE-2026-72792.
### Summary
`/api/tag/getTag` filters its results for reader roles through `FilterTagsByPublishIgnore`, which checks o
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-72792cve
- http://127.0.0.1:6808/api/tag/getTagurl
Original source: https://github.com/advisories/GHSA-mp7r-57w4-5qm3