cbcvebase.

Github.Com Siyuan-Note Siyuan Kernel vulnerabilities

94 known vulnerabilities affecting github.com/siyuan-note_siyuan_kernel.

Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH38MEDIUM33LOW2

Vulnerabilities

Page 1 of 5
CVE-2026-54066P1HIGHCVSS 7.1ExploitedPoC≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54066 [HIGH] CWE-1188 SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 ## Summary The patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the `/export/` route but the **identical root cause remains in the `/assets/*path` route**. In publish mode (
ghsa
CVE-2026-69084P2CRITICALCVSS 10.0PoC≥ 0, < 0.0.0-20260721002947-23a17d44b5f32026-09-03
CVE-2026-69084 [CRITICAL] SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write **CVE:** This vulnerability corresponds to [CVE-2026-69084](https://nvd.nist.gov/vuln/detail/CVE-2026-69084). ### Summary The `/api/search/se
ghsa
CVE-2026-69085P2CRITICALCVSS 10.0PoC≥ 0, ≤ 3.7.22026-08-03
CVE-2026-69085 [CRITICAL] CWE-89 Duplicate Advisory: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking Duplicate Advisory: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-33jq-p8c2-q3q4. This link is maintained to preserve external references.
ghsa
CVE-2026-33476P2HIGHPoC≥ 0, ≤ 0.0.0-20260317012524-fe4523fff2c82026-03-20
CVE-2026-33476 [HIGH] CWE-22 Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal ## Summary The Siyuan kernel exposes an unauthenticated file-serving endpoint under **/appearance/*filepath.** Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation witho
ghsaosv
CVE-2026-54069P2CRITICALPoC≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54069 [CRITICAL] CWE-346 SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist ## Summary SiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/
ghsa
CVE-2026-34453P2HIGHPoC≥ 0, < 3.6.22026-03-31
CVE-2026-34453 [HIGH] CWE-863 SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmark SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmark ### Summary The publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, `/api/bookmark/getBookmark` filters bookmark results by calling `FilterBlocksByPublishAccess(nil, ...)`. Because the filter treats a `n
ghsaosv
CVE-2026-30869P2CRITICALCVSS 9.8≥ 0, < 3.6.52026-04-22
CVE-2026-30869 [CRITICAL] CWE-22 SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869) SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869) ### Summary The fix for CVE-2026-30869 in SiYuan v3.5.10 only added a denylist check (`IsSensitivePath`) but did not address the root cause — a redundant `url.PathUnescape()` call in `serveExport()`. An authenticated attacker can use double
ghsaosv
CVE-2026-69083P2CRITICALCVSS 10.0≥ 0, < 0.0.0-20260721004815-cf42dd5680c82026-09-03
CVE-2026-69083 [CRITICAL] SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-conten SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB **CVE:** This vulnerability corresponds to [CVE-2026-69083](https:/
ghsa
CVE-2026-72811P2CRITICALCVSS 10.0≥ 0, < 0.0.0-20260723004839-1a5b3431d5ab2026-09-03
CVE-2026-72811 [CRITICAL] CWE-89 SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write hand SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle **CVE:** This vulnerability corresponds to [CVE-2026-72811](ht
ghsa
CVE-2026-31809P3MEDIUMCVSS 6.1PoC≥ 0, < 0.0.0-20260310025236-297bd526708f2026-03-10
CVE-2026-31809 [MEDIUM] CWE-79 SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS # SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS ## Summary SiYuan's SVG sanitizer (`SanitizeSVG`) checks `href` attributes for the `javascript:` prefix using `strings.HasPrefix()`. However, inserting ASCII tab (` `), newline (` `), or carriage retur
ghsaosv
CVE-2026-31807P3MEDIUMCVSS 6.1PoC≥ 0, < 0.0.0-20260310025236-297bd526708f2026-03-10
CVE-2026-31807 [MEDIUM] CWE-79 SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS SiYuan has a SVG Sanitizer Bypass via `` Element — Unauthenticated XSS # SVG Sanitizer Bypass via `` Element — Unauthenticated XSS ## Summary SiYuan's SVG sanitizer (`SanitizeSVG`) blocks dangerous elements (``, ``, ``) and removes `on*` event handlers and `javascript:` in `href` attributes. However, it does NOT block SVG animation elements (``, ``) which can dynamically set attribut
ghsaosv
CVE-2026-32767P2CRITICAL≥ 0, ≤ 0.0.0-20260313024916-fd6526133bb32026-03-16
CVE-2026-32767 [CRITICAL] CWE-863 SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API ## Summary SiYuan Note v3.6.0 (and likely prior versions) contains an authorization bypass vulnerability in the `/api/search/fullTextSearchBlock` endpoint. When the `method` parameter is set to `2`, the endpoint passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without a
ghsaosv
CVE-2026-29183P3CRITICALPoC≥ 0, < 0.0.0-20260304034809-d68bd5a793912026-03-04
CVE-2026-29183 [CRITICAL] CWE-79 SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint ### Summary An unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint: - `GET /api/icon/getDynamicIcon` When `type=8`, attacker-controlled `content` is embedded into SVG output without escaping. Because the endpoint is unauthenticated and returns `i
ghsaosv
CVE-2026-54067P2CRITICAL≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54067 [CRITICAL] CWE-1188 SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() SiYuan: Stored XSS to RCE via CSS-snippet breakout in renderSnippet() ### Summary A CSS snippet body containing `` breaks out of its surrounding `` tag when `renderSnippet()` interpolates it via `insertAdjacentHTML`. A payload like `` runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer runs with `nodeIntegration:true`, so `require('child_process')` is
ghsa
CVE-2026-34449P2CRITICAL≥ 0, < 3.6.22026-03-31
CVE-2026-34449 [CRITICAL] CWE-942 SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection ### Summary A malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (`Access-Control-Allow-Origin: *` + `Access-Control-Allow-Private-Network: true`) to inject a JavaScript snippet via th
ghsaosv
CVE-2026-34605P3HIGHPoC≥ 0, < 0.0.0-20260330031106-f09953afc57a2026-04-01
CVE-2026-34605 [HIGH] CWE-79 SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated) SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated) ### Summary The `SanitizeSVG` function introduced in v3.6.0 to fix XSS in the unauthenticated `/api/icon/getDynamicIcon` endpoint can be bypassed by using namespace-prefixed element names such as ``. The Go HTML5 parser records the eleme
ghsaosv
CVE-2026-72794P3HIGHCVSS 8.6≥ 0, < 0.0.0-20260725123945-77421530be4a2026-09-04
CVE-2026-72794 [HIGH] CWE-522 SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf **CVE:** This vulnerability corresponds to [CVE-2026-72794](https://nvd.nist.gov/vuln/detail/CVE-2026-72794). ### Summary `/api/system/getConf` returns `Conf.CookieKey`, the key used to sign the server's session cookies in its response body. T
ghsa
CVE-2026-54158P2CRITICAL≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54158 [CRITICAL] CWE-1188 SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() ### Summary The attribute-view (database) cell renderer `genAVValueHTML` interpolates cell content raw in four of its branches: `text`, `url`, `phone`, and `mAsset`. A cell value like `` or `">` breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the victim opens the bl
ghsa
CVE-2026-68584P3HIGHCVSS 8.6≥ 0, < 0.0.0-20260721020826-2d069dce84a22026-09-03
CVE-2026-68584 [HIGH] CWE-288 SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) **CVE:** This vulnerability corresponds to [CVE-2026-68584](https://nvd.nist.gov/vuln/detail/CVE-2026-68584). ### Summary SiYuan's publish mode defines a "protected" access level: a docum
ghsa
CVE-2026-50551P3CRITICALCVSS 9.4≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-50551 [CRITICAL] CWE-79 SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content SiYuan v3.6.5 and earlier versions contain a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This is a neighbor-bug of CVE-2026-44588: the fix for -44588 used `escapeAriaLabel()` (dou
ghsa
Github.Com Siyuan-Note Siyuan Kernel vulnerabilities | cvebase