GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35 advisories
Filter by severity
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Critical
CVE-2026-69085
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
CVE-2026-72792
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
CVE-2026-72796
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
Moderate
CVE-2026-72797
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
CVE-2026-72799
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
Moderate
CVE-2026-72800
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
CVE-2026-72801
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
CVE-2026-72802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
Moderate
CVE-2026-72803
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
High
CVE-2026-72804
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
Moderate
CVE-2026-72805
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
Moderate
CVE-2026-72806
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
CVE-2026-72807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
Moderate
CVE-2026-72808
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API