Vulnerability GO-2026-6657
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
7 hours ago
October 07, 2026 at 02:10 PM UTC
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260813142806-dd2778b70d02
<0.0.0-20260813142806-dd2778b70d02
Summary
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) in github.com/siyuan-note/siyuan/kernel
Details
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) in github.com/siyuan-note/siyuan/kernel
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
7 hours ago
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/* in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260816034002-035bf9a8c311 GO-2026-6662
<0.0.0-20260816034002-035bf9a8c311 GO-2026-6662
Unknown
7 hours ago
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist) in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260819144130-256d73aa7f94 GO-2026-6663
<0.0.0-20260819144130-256d73aa7f94 GO-2026-6663
Unknown
7 hours ago
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260813142104-b26a4a307b8a GO-2026-6655
<0.0.0-20260813142104-b26a4a307b8a GO-2026-6655
Unknown
7 hours ago
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260721043339-eef10568384e GO-2026-6621
<0.0.0-20260721043339-eef10568384e GO-2026-6621
Unknown
7 hours ago
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block in github.com/siyuan-note/siyuan/kernel
<0.0.0-20260812083335-251596fc0de2 GO-2026-6635
<0.0.0-20260812083335-251596fc0de2 GO-2026-6635
Impacted packages
Timeline
Published
7 hours ago
October 07, 2026 at 02:10 PM UTC
Last Modified
3 hours ago
October 07, 2026 at 05:55 PM UTC