<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pdf-Processing - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/pdf-processing/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 20:54:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/pdf-processing/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in SiYuan Publish API</title><link>https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/</link><pubDate>Wed, 12 Aug 2026 20:54:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-siyuan-auth-bypass/</guid><description>SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.</description><content:encoded><![CDATA[<p>SiYuan versions before 3.7.4 contain a critical authentication bypass vulnerability (CVE-2026-72789) within the application's publish API. The defect stems from an improper access control validation logic where encrypted notebooks are incorrectly treated as publicly accessible by default. When a user has unlocked an encrypted notebook, the application fails to verify the requestor's authorization, enabling anonymous remote users to enumerate and exfiltrate decrypted document content. This flaw allows attackers to bypass intended security boundaries without possessing the necessary encryption keys. Defenders should prioritize updating to v3.7.4 or later to remediate this improper authorization, which significantly exposes sensitive notebook data to unauthorized disclosure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized disclosure of sensitive, encrypted document content. Any notebook that has been unlocked by a user becomes vulnerable to retrieval by unauthenticated parties through the publish API. This impacts all SiYuan deployments currently running versions earlier than 3.7.4 that utilize the notebook publishing feature.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all SiYuan instances to version 3.7.4 or later immediately to patch the access control flaw.</li>
<li>Audit webserver access logs for high volumes of unexpected GET requests to the publish API endpoints from unauthorized IP addresses.</li>
<li>Disable the publish API feature temporarily if an immediate update to v3.7.4 is not feasible.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>access-control</category><category>web-vulnerability</category><category>authentication-bypass</category><category>information-disclosure</category><category>api-security</category><category>remote-code-execution</category><category>vulnerability</category><category>pdf-processing</category><category>credential-access</category><category>web-application</category></item></channel></rss>