data/reports: add 7 reports

  - data/reports/GO-2026-6621.yaml
  - data/reports/GO-2026-6622.yaml
  - data/reports/GO-2026-6624.yaml
  - data/reports/GO-2026-6626.yaml
  - data/reports/GO-2026-6632.yaml
  - data/reports/GO-2026-6634.yaml
  - data/reports/GO-2026-6635.yaml

Fixes golang/vulndb#6621
Fixes golang/vulndb#6622
Fixes golang/vulndb#6624
Fixes golang/vulndb#6626
Fixes golang/vulndb#6632
Fixes golang/vulndb#6634
Fixes golang/vulndb#6635

Change-Id: I818eb7c51df3595466020a65a105fb2db7032b13
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/843685
Auto-Submit: Ian Alexander <jitsu@google.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6621.json b/data/osv/GO-2026-6621.json
new file mode 100644
index 0000000..3027ddf
--- /dev/null
+++ b/data/osv/GO-2026-6621.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6621",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-69085",
+    "GHSA-33jq-p8c2-q3q4"
+  ],
+  "summary": "SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260721043339-eef10568384e"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69085"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6621",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6622.json b/data/osv/GO-2026-6622.json
new file mode 100644
index 0000000..4a0920b
--- /dev/null
+++ b/data/osv/GO-2026-6622.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6622",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-72788",
+    "GHSA-hgfg-j9pg-43xw"
+  ],
+  "summary": "SiYuan discloses an administrator's open documents and search terms to anonymous readers in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan discloses an administrator's open documents and search terms to anonymous readers in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hgfg-j9pg-43xw"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72788"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-uilayout-filter"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6622",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6624.json b/data/osv/GO-2026-6624.json
new file mode 100644
index 0000000..2c0b411
--- /dev/null
+++ b/data/osv/GO-2026-6624.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6624",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-73607",
+    "GHSA-53fp-9jmv-227g"
+  ],
+  "summary": "SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73607"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6624",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6626.json b/data/osv/GO-2026-6626.json
new file mode 100644
index 0000000..91a44ec
--- /dev/null
+++ b/data/osv/GO-2026-6626.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6626",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-73605",
+    "GHSA-hf8h-97gm-4x2p"
+  ],
+  "summary": "SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73605"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6626",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6632.json b/data/osv/GO-2026-6632.json
new file mode 100644
index 0000000..f25ac6b
--- /dev/null
+++ b/data/osv/GO-2026-6632.json
@@ -0,0 +1,51 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6632",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-9cqf-hhrq-7v45"
+  ],
+  "summary": "SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.0.0-20260726161145-9b8e8956f997"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqf-hhrq-7v45"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/commit/9b8e8956f997d6452d40aff4159d58f3283a98a4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6632",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6634.json b/data/osv/GO-2026-6634.json
new file mode 100644
index 0000000..e778859
--- /dev/null
+++ b/data/osv/GO-2026-6634.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6634",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-73609",
+    "GHSA-j4ph-9xwf-wcj4"
+  ],
+  "summary": "SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73609"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarklabels"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6634",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6635.json b/data/osv/GO-2026-6635.json
new file mode 100644
index 0000000..ec6f471
--- /dev/null
+++ b/data/osv/GO-2026-6635.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6635",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-73606",
+    "GHSA-vg99-7gj7-2fr5"
+  ],
+  "summary": "SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260812083335-251596fc0de2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73606"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6635",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6621.yaml b/data/reports/GO-2026-6621.yaml
new file mode 100644
index 0000000..fbf8bf3
--- /dev/null
+++ b/data/reports/GO-2026-6621.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6621
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260721043339-eef10568384e
+summary: |-
+    SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword
+    (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-69085
+ghsas:
+    - GHSA-33jq-p8c2-q3q4
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69085
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3
+    - web: https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-33jq-p8c2-q3q4
+    created: 2026-10-02T13:22:05.244551-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6622.yaml b/data/reports/GO-2026-6622.yaml
new file mode 100644
index 0000000..683f945
--- /dev/null
+++ b/data/reports/GO-2026-6622.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6622
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan discloses an administrator's open documents and search terms to anonymous
+    readers in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-72788
+ghsas:
+    - GHSA-hgfg-j9pg-43xw
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hgfg-j9pg-43xw
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-72788
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
+    - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-uilayout-filter
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-hgfg-j9pg-43xw
+    created: 2026-10-02T13:21:55.800966-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6624.yaml b/data/reports/GO-2026-6624.yaml
new file mode 100644
index 0000000..9f08d8b
--- /dev/null
+++ b/data/reports/GO-2026-6624.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6624
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan: Outline state for any document, including documents forbidden to
+    readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-73607
+ghsas:
+    - GHSA-53fp-9jmv-227g
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73607
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
+    - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-53fp-9jmv-227g
+    created: 2026-10-02T13:21:44.594443-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6626.yaml b/data/reports/GO-2026-6626.yaml
new file mode 100644
index 0000000..e4488f1
--- /dev/null
+++ b/data/reports/GO-2026-6626.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6626
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the
+    filesystem, giving anonymous readers an existence oracle over the entire host
+    filesystem in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-73605
+ghsas:
+    - GHSA-hf8h-97gm-4x2p
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73605
+    - web: https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-hf8h-97gm-4x2p
+    created: 2026-10-02T13:21:02.300341-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6632.yaml b/data/reports/GO-2026-6632.yaml
new file mode 100644
index 0000000..9ad23d5
--- /dev/null
+++ b/data/reports/GO-2026-6632.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6632
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - introduced: 0.0.0-20260726161145-9b8e8956f997
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan: getAttributeViewSearchTarget returns database row content to anonymous
+    readers with no publish-access check, reopening the class closed one day earlier
+    at the adjacent route in github.com/siyuan-note/siyuan/kernel
+ghsas:
+    - GHSA-9cqf-hhrq-7v45
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqf-hhrq-7v45
+    - web: https://github.com/siyuan-note/siyuan/commit/9b8e8956f997d6452d40aff4159d58f3283a98a4
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-9cqf-hhrq-7v45
+    created: 2026-10-02T13:20:48.845028-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6634.yaml b/data/reports/GO-2026-6634.yaml
new file mode 100644
index 0000000..b28ca44
--- /dev/null
+++ b/data/reports/GO-2026-6634.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6634
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan: getBookmarkLabels returns every bookmark label in the workspace to
+    anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-73609
+ghsas:
+    - GHSA-j4ph-9xwf-wcj4
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73609
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
+    - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarklabels
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-j4ph-9xwf-wcj4
+    created: 2026-10-02T13:20:38.501624-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6635.yaml b/data/reports/GO-2026-6635.yaml
new file mode 100644
index 0000000..ab7301f
--- /dev/null
+++ b/data/reports/GO-2026-6635.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6635
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260812083335-251596fc0de2
+summary: |-
+    SiYuan: The reference filter for getRefIDs checks visibility but not the
+    password tier, disclosing that password-protected documents reference a given
+    block in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-73606
+ghsas:
+    - GHSA-vg99-7gj7-2fr5
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73606
+    - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
+    - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-vg99-7gj7-2fr5
+    created: 2026-10-02T13:18:51.916336-04:00
+review_status: UNREVIEWED