Endpunktsicherheit
🟠 CVE-2026-68586: High Schwachstelle
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the...
🟠 CVE-2026-68584: High Schwachstelle
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform...
🔴 CVE-2026-69085: Critical Schwachstelle
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly...
🔴 CVE-2026-69084: Critical Schwachstelle
SiYuan versions
🔴 CVE-2026-69083: Critical Schwachstelle
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens....
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys...
ENDPUNKTSICHERHEIT
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint,...
🟡 CVE-2026-68582: Medium Schwachstelle
Vikunja versions >= 0.24.0 and
🟠 CVE-2025-71400: High Schwachstelle
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated...
🟠 CVE-2026-68581: High Schwachstelle
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share...