THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v684-q882-jgmq (high) — SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

[GHSA] GHSA-v684-q882-jgmq (high) — SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

highgithub_advisoriesPublished 2026-09-08

GHSA-v684-q882-jgmq Severity: high CVE: CVE-2026-72789

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

**CVE:** This vulnerability corresponds to CVE-2026-72789.

### Summary

`publishAccess.json` is

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v684-q882-jgmq