data/reports: add 7 reports - data/reports/GO-2026-6621.yaml - data/reports/GO-2026-6622.yaml - data/reports/GO-2026-6624.yaml - data/reports/GO-2026-6626.yaml - data/reports/GO-2026-6632.yaml - data/reports/GO-2026-6634.yaml - data/reports/GO-2026-6635.yaml Fixes golang/vulndb#6621 Fixes golang/vulndb#6622 Fixes golang/vulndb#6624 Fixes golang/vulndb#6626 Fixes golang/vulndb#6632 Fixes golang/vulndb#6634 Fixes golang/vulndb#6635 Change-Id: I818eb7c51df3595466020a65a105fb2db7032b13 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/843685 Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Nicholas Husin <nsh@golang.org> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6621.json b/data/osv/GO-2026-6621.json new file mode 100644 index 0000000..3027ddf --- /dev/null +++ b/data/osv/GO-2026-6621.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6621", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-69085", + "GHSA-33jq-p8c2-q3q4" + ], + "summary": "SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260721043339-eef10568384e" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69085" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6621", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6622.json b/data/osv/GO-2026-6622.json new file mode 100644 index 0000000..4a0920b --- /dev/null +++ b/data/osv/GO-2026-6622.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6622", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-72788", + "GHSA-hgfg-j9pg-43xw" + ], + "summary": "SiYuan discloses an administrator's open documents and search terms to anonymous readers in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan discloses an administrator's open documents and search terms to anonymous readers in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hgfg-j9pg-43xw" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72788" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-uilayout-filter" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6622", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6624.json b/data/osv/GO-2026-6624.json new file mode 100644 index 0000000..2c0b411 --- /dev/null +++ b/data/osv/GO-2026-6624.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6624", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73607", + "GHSA-53fp-9jmv-227g" + ], + "summary": "SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73607" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6624", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6626.json b/data/osv/GO-2026-6626.json new file mode 100644 index 0000000..91a44ec --- /dev/null +++ b/data/osv/GO-2026-6626.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6626", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73605", + "GHSA-hf8h-97gm-4x2p" + ], + "summary": "SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73605" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6626", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6632.json b/data/osv/GO-2026-6632.json new file mode 100644 index 0000000..f25ac6b --- /dev/null +++ b/data/osv/GO-2026-6632.json
@@ -0,0 +1,51 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6632", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-9cqf-hhrq-7v45" + ], + "summary": "SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.0.0-20260726161145-9b8e8956f997" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqf-hhrq-7v45" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/commit/9b8e8956f997d6452d40aff4159d58f3283a98a4" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6632", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6634.json b/data/osv/GO-2026-6634.json new file mode 100644 index 0000000..e778859 --- /dev/null +++ b/data/osv/GO-2026-6634.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6634", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73609", + "GHSA-j4ph-9xwf-wcj4" + ], + "summary": "SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73609" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarklabels" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6634", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6635.json b/data/osv/GO-2026-6635.json new file mode 100644 index 0000000..ec6f471 --- /dev/null +++ b/data/osv/GO-2026-6635.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6635", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73606", + "GHSA-vg99-7gj7-2fr5" + ], + "summary": "SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260812083335-251596fc0de2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73606" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6635", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6621.yaml b/data/reports/GO-2026-6621.yaml new file mode 100644 index 0000000..fbf8bf3 --- /dev/null +++ b/data/reports/GO-2026-6621.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6621 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260721043339-eef10568384e +summary: |- + SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword + (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-69085 +ghsas: + - GHSA-33jq-p8c2-q3q4 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69085 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3 + - web: https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-33jq-p8c2-q3q4 + created: 2026-10-02T13:22:05.244551-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6622.yaml b/data/reports/GO-2026-6622.yaml new file mode 100644 index 0000000..683f945 --- /dev/null +++ b/data/reports/GO-2026-6622.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6622 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan discloses an administrator's open documents and search terms to anonymous + readers in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-72788 +ghsas: + - GHSA-hgfg-j9pg-43xw +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hgfg-j9pg-43xw + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-72788 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0 + - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-uilayout-filter +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-hgfg-j9pg-43xw + created: 2026-10-02T13:21:55.800966-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6624.yaml b/data/reports/GO-2026-6624.yaml new file mode 100644 index 0000000..9f08d8b --- /dev/null +++ b/data/reports/GO-2026-6624.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6624 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan: Outline state for any document, including documents forbidden to + readers, is returned by /api/storage/getOutlineStorage with no access check in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-73607 +ghsas: + - GHSA-53fp-9jmv-227g +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73607 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0 + - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-53fp-9jmv-227g + created: 2026-10-02T13:21:44.594443-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6626.yaml b/data/reports/GO-2026-6626.yaml new file mode 100644 index 0000000..e4488f1 --- /dev/null +++ b/data/reports/GO-2026-6626.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6626 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the + filesystem, giving anonymous readers an existence oracle over the entire host + filesystem in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-73605 +ghsas: + - GHSA-hf8h-97gm-4x2p +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73605 + - web: https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-hf8h-97gm-4x2p + created: 2026-10-02T13:21:02.300341-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6632.yaml b/data/reports/GO-2026-6632.yaml new file mode 100644 index 0000000..9ad23d5 --- /dev/null +++ b/data/reports/GO-2026-6632.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6632 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - introduced: 0.0.0-20260726161145-9b8e8956f997 + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan: getAttributeViewSearchTarget returns database row content to anonymous + readers with no publish-access check, reopening the class closed one day earlier + at the adjacent route in github.com/siyuan-note/siyuan/kernel +ghsas: + - GHSA-9cqf-hhrq-7v45 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqf-hhrq-7v45 + - web: https://github.com/siyuan-note/siyuan/commit/9b8e8956f997d6452d40aff4159d58f3283a98a4 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-9cqf-hhrq-7v45 + created: 2026-10-02T13:20:48.845028-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6634.yaml b/data/reports/GO-2026-6634.yaml new file mode 100644 index 0000000..b28ca44 --- /dev/null +++ b/data/reports/GO-2026-6634.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6634 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan: getBookmarkLabels returns every bookmark label in the workspace to + anonymous readers, with no publish-access filtering in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-73609 +ghsas: + - GHSA-j4ph-9xwf-wcj4 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73609 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0 + - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarklabels +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-j4ph-9xwf-wcj4 + created: 2026-10-02T13:20:38.501624-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6635.yaml b/data/reports/GO-2026-6635.yaml new file mode 100644 index 0000000..ab7301f --- /dev/null +++ b/data/reports/GO-2026-6635.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6635 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260812083335-251596fc0de2 +summary: |- + SiYuan: The reference filter for getRefIDs checks visibility but not the + password tier, disclosing that password-protected documents reference a given + block in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-73606 +ghsas: + - GHSA-vg99-7gj7-2fr5 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-73606 + - web: https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0 + - web: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-vg99-7gj7-2fr5 + created: 2026-10-02T13:18:51.916336-04:00 +review_status: UNREVIEWED