—
GO-2026-6425
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
Quick fix
GO-2026-6425 — github.com/siyuan-note/siyuan/kernel: upgrade to the fixed version with the command below.
go get github.com/siyuan-note/siyuan/kernel@v0.0.0-20260725125659-1ca1c3c9d94bDetails
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/siyuan-note/siyuan/kernel
Introduced in:
0Fixed in: 0.0.0-20260725125659-1ca1c3c9d94bFix
go get github.com/siyuan-note/siyuan/kernel@v0.0.0-20260725125659-1ca1c3c9d94bReferences
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h6w7-xxcf-w2mq[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-72795[ADVISORY]
- https://github.com/siyuan-note/siyuan/commit/1ca1c3c9d94bea14fc9728ff2fb8392bb0f29732[WEB]
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-embed-block[WEB]