AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-73609.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 01, 2026

Disclosure summary

### Summary `/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label in the workspace. An anonymous reader in publish mode receives the author's complete bookmark vocabulary, regardless of whether the bookmarked blocks live in published, hidden, password-protected or forbidden documents. The adjacent endpoint that returns bookmarks with their blocks does filter, and does so in a way that makes the intended rule explicit: it drops a label entirely when no accessible block carries it. ### Details **Route.** `kernel/api/router.go:297` on master, `:300` on the development branch: ```go ginServer.Handle("POST", "/api/attr/getBookmarkLabels", model.CheckAuth, getBookmarkLabels) ``` No `CheckAdminRole`, no `CheckReadonly`. Reachable by the publish `RoleReader` token and anonymously when `Publish.Auth.Enable` is `false`. **The handler** (`kernel/api/attr.go`) is a single line: ```go ret.Data = model.BookmarkLabels() ``` which reaches `kernel/model/bookmark.go:184` and then `sql.QueryBookmarkLabels()` at `kernel/sql/block_query.go:315`: ```go sqlStm

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-j4ph-9xwf-wcj4

Open original source · Updated Oct 01, 2026

SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/siyuan-note/siyuan/kernel< 0.0.0-20260812083335-251596fc0de20.0.0-20260812083335-251596fc0de2

Original records & references

PUBLISHED 2026-10-01T12:23:37-04:00
MODIFIED 2026-10-01T12:23:39-04:00
INGESTED 2026-10-06T11:45:02-04:00