{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/siyuan-development-branch/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-73608"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan (Development Branch)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eA missing authorization check has been identified in the SiYuan development branch at the /api/av/getAttributeViewSearchTarget endpoint (introduced by commit 9b8e8956f). The vulnerability allows anonymous users to query database content on published pages by providing a database identifier and a keyword. Because the endpoint registers only with 'CheckAuth' but lacks essential 'CheckReadonly', 'publish-access', or 'encrypted-notebook' gating, it effectively bypasses row-level security and filtering mechanisms designed to protect sensitive data.\u003c/p\u003e\n\u003cp\u003eWhile the base score for this vulnerability is 8.6, it is important to note that this flaw is restricted to the development branch and does not affect stable releases such as v3.7.3 or the current master branch. The issue was patched in v3.7.4. Defenders should ensure no development branches are deployed in production environments, as these versions may expose internal APIs to external exposure that are not gated for public access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated, remote attacker to exfiltrate database content that should otherwise be withheld by the application's native publish-access filters. This results in unauthorized disclosure of sensitive data managed within SiYuan database views.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure that only stable, production-ready versions (v3.7.3 or v3.7.4) of SiYuan are deployed in your environment.\u003c/li\u003e\n\u003cli\u003eAudit infrastructure to identify and decommission any instances running development branch builds of SiYuan.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unauthorized access patterns or unexpected requests to the /api/av/getAttributeViewSearchTarget endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T12:54:56Z","date_published":"2026-08-13T12:54:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/","summary":"The SiYuan development branch contains an authorization bypass vulnerability in the /api/av/getAttributeViewSearchTarget endpoint, allowing unauthenticated users to access restricted database content.","title":"Authorization Bypass in SiYuan Development Branch","url":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SiYuan (Development Branch)","version":"https://jsonfeed.org/version/1.1"}