THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mp7r-57w4-5qm3 (medium) — SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

[GHSA] GHSA-mp7r-57w4-5qm3 (medium) — SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

highgithub_advisoriesPublished 2026-09-04

GHSA-mp7r-57w4-5qm3 Severity: medium CVE: CVE-2026-72792

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

**CVE:** This vulnerability corresponds to CVE-2026-72792.

### Summary

`/api/tag/getTag` filters its results for reader roles through `FilterTagsByPublishIgnore`, which checks o

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mp7r-57w4-5qm3