SiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
Published May 14, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.25%
Description
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded by both. Any authenticated user — including publish-service RoleReader accounts and RoleEditor accounts on a read-only workspace — can call this endpoint with a sort argument to mutate model.Conf.Tag.Sort and trigger model.Conf.Save(), which atomically rewrites the entire workspace conf.json. This vulnerability is fixed in 3.7.0.
Affected products
-
- Version < 3.7.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Siyuan-Note | Siyuan | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/siyuan-note/siyuan/kernel
Go
Introduced 0 Fixed 0.0.0-20260512140701-d7b77d945e0d
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/siyuan-note/siyuan/kernel | 0 | 0.0.0-20260512140701-d7b77d945e0d |
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30360 Advisory
- https://github.com/advisories/GHSA-6r88-8v7q-q4p2 Advisory
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6r88-8v7q-q4p2 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-45147
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30360 | Advisory | |
| https://github.com/advisories/GHSA-6r88-8v7q-q4p2 | Advisory | |
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6r88-8v7q-q4p2 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45147 |
Change history (0)
No recorded changes yet.