Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GO-2026-6386
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6387
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6388
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6392
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6395
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6398
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6400
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6402
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6404
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6406
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6407
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6408
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6410
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6411
    Fix available
    Packages

    github.com/googleapis/mcp-toolbox

    Summary

    MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox

    Published
    10 Sept 2026
    GO-2026-6412
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6414
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6415
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6420
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6423
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6424
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6425
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6427
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6428
    Fix available
    Packages

    github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo

    Published
    10 Sept 2026
    GO-2026-6430
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6431
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6433
    Fix available
    Packages

    code.gitea.io/gitea, gitea.dev

    Summary

    Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

    Published
    10 Sept 2026
    GO-2026-6434
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6435
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore

    Published
    10 Sept 2026
    GO-2026-6437
    Fix available
    Packages

    github.com/infracost/infracost

    Summary

    Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost

    Published
    10 Sept 2026
    GO-2026-6439
    Fix available
    Packages

    github.com/infracost/infracost

    Summary

    Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost

    Published
    10 Sept 2026
    GO-2026-6440
    Fix available
    Packages

    github.com/amir20/dozzle

    Summary

    Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle

    Published
    10 Sept 2026
    CVE-2026-88007
    Fix available
    Packages

    Summary

    Traefik HTTP/3 Backend NTLM Connection Reuse

    Published
    10 Sept 2026
    CVE-2026-88898
    No fix available
    Packages

    Summary

    AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint

    Published
    10 Sept 2026
    CVE-2026-88897
    No fix available
    Packages

    Summary

    Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String

    Published
    10 Sept 2026
    CGA-pmcf-93fq-hr9g
    Fix available
    Packages

    envoy-gateway-fips-1.7-egctl

    Summary

    Published
    10 Sept 2026
    CGA-jw66-2g4h-v4rx
    Fix available
    Packages

    crossplane-cli-fips-2.3

    Summary

    Published
    10 Sept 2026
    CVE-2026-88006
    Fix available
    Packages

    Summary

    Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

    Published
    10 Sept 2026
    CGA-fg28-vwf4-6w2m
    No fix available
    Packages

    chartmuseum, chartmuseum

    Summary

    Published
    10 Sept 2026
    CGA-hqcq-p2wc-cc77
    Fix available
    Packages

    dogstatsd-7.81, dogstatsd-7.81

    Summary

    Published
    10 Sept 2026
    CVE-2026-88005
    Fix available
    Packages

    Summary

    Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

    Published
    10 Sept 2026
    CGA-89q2-53m5-4pwf
    No fix available
    Packages

    datadog-agent-fips-7.81

    Summary

    Published
    10 Sept 2026
    CGA-hh48-xj92-p27c
    No fix available
    Packages

    datadog-agent-fips-7.81

    Summary

    Published
    10 Sept 2026
    CGA-3p6q-m2gx-44gp
    No fix available
    Packages

    datadog-agent-fips-7.81

    Summary

    Published
    10 Sept 2026
    CGA-5grc-qw8j-49wp
    No fix available
    Packages

    datadog-agent-7.76, datadog-agent-7.76

    Summary

    Published
    10 Sept 2026
    CVE-2026-15461
    Fix available
    Packages

    Summary

    Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input

    Published
    10 Sept 2026
    CVE-2026-88004
    Fix available
    Packages

    Summary

    Traefik entrypoint header-name sanitization bypassed via request trailers

    Published
    10 Sept 2026
    CGA-vqw4-x838-w4xj
    No fix available
    Packages

    docker-compose-fips

    Summary

    Published
    10 Sept 2026
    CGA-mpxh-8p45-ccjx
    No fix available
    Packages

    dogstatsd-7.81, dogstatsd-7.81

    Summary

    Published
    10 Sept 2026
    Packages

    nodemailer

    Summary

    TuxCare security update for nodemailer (7 CVEs)

    Published
    10 Sept 2026
    CGA-q6jv-v3j6-fgfv
    Fix available
    Packages

    consul-k8s-1.3-cli

    Summary

    Published
    10 Sept 2026