GHSA-v684-q882-jgmq: SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymo
HIGHHigh-risk vulnerability — CVSS 8.6
**CVE:** This vulnerability corresponds to [CVE-2026-72789](https://nvd.nist.gov/vuln/detail/CVE-2026-72789). ### Summary `publishAccess.json` is an opt-out list. The publish gate returns *accessible* for anything not explicitly listed in it. Encrypted notebooks are never written into that file, because only the administrator-gated `setPublishAccess` writes it and no part of the encryption subsystem does. Consequently every encrypted notebook is publish-accessible as far as the gate is concerned. …
CVE · detail
- CVE-2026-72789nvd ↗EPSS 0.29%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected