AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-74904.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`) anywhere in the function body. 17 of 28 candidate endpoints have none. Cross-checked against the file's own sibling functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which correctly implement the check, confirming this is a real, uneven gap rather than a deliberate design choice for the whole file. ### Summary 17 handlers in `kernel/api/block.go`, all gated only by `model.CheckAuth` with no admin-role requirement, return block content-derived text, structural metadata, or existence information for any block ID supplied, with no access check anywhere in the handler or, for the ones checked in detail, the model functions they call. This is CWE-862 (Missing Authorization), the same class as the companion advisories from this review round, found in a different file via a systematic bulk check rather than manual inspection of each function individually. ### Details Confirmed via automated extraction of every function body between `func NAME(c *gin

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-4vpg-gwqq-w44c

Open original source · Updated Oct 02, 2026

SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/siyuan-note/siyuan/kernel< 0.0.0-20260804015139-bd067a4fe9b20.0.0-20260804015139-bd067a4fe9b2

Original records & references

PUBLISHED 2026-10-02T19:05:33-04:00
MODIFIED 2026-10-02T19:05:34-04:00
INGESTED 2026-10-06T11:45:17-04:00