Skip to content
archivevulnerability · 08 Sep 2026 · 17:56 UTC

GHSA-v684-q882-jgmq: SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymo

VULNCVE-2026-72789source · GTH
HIGHHigh-risk vulnerability — CVSS 8.6

last 60 dispatches · spectrum

**CVE:** This vulnerability corresponds to [CVE-2026-72789](https://nvd.nist.gov/vuln/detail/CVE-2026-72789). ### Summary `publishAccess.json` is an opt-out list. The publish gate returns *accessible* for anything not explicitly listed in it. Encrypted notebooks are never written into that file, because only the administrator-gated `setPublishAccess` writes it and no part of the encryption subsystem does. Consequently every encrypted notebook is publish-accessible as far as the gate is concerned. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected