cbcvebase.

Github.Com Siyuan-Note Siyuan Kernel vulnerabilities

94 known vulnerabilities affecting github.com/siyuan-note_siyuan_kernel.

Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH38MEDIUM33LOW2

Vulnerabilities

Page 3 of 5
CVE-2026-40259P3HIGH≥ 0, < 0.0.0-20260407035653-2f416e5253f12026-04-10
CVE-2026-40259 [HIGH] CWE-285 SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView` SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView` ## Summary An authenticated publish-service reader can invoke `/api/av/removeUnusedAttributeView` and cause persistent deletion of arbitrary attribute view (`AV`) definition files from the workspace. The route is protected only by generic `CheckAuth`, w
ghsa
CVE-2026-69086P3HIGHCVSS 7.7≥ 0, < 0.0.0-20260720151813-0f5a0e7c67b02026-09-03
CVE-2026-69086 [HIGH] CWE-22 SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure **CVE:** This vulnerability corresponds to [CVE-2026-69086](https://nvd.nist.gov/vuln/detail/CVE-2026-69086). ### Summary Four attribute-view read endpoints build a filesystem path fro
ghsa
CVE-2026-25539P3CRITICAL≥ 0, ≤ 0.0.0-20260126094835-d5d10dd41b0c2026-01-29
CVE-2026-25539 [CRITICAL] CWE-22 SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE ## Summary The `/api/file/copyFile` endpoint does not validate the `dest` parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. - Af
ghsaosv
CVE-2026-59832P3CRITICALCVSS 9.8≥ 0, < 0.0.0-20260704035520-68cc0f537dfa2026-09-02
CVE-2026-59832 [CRITICAL] CWE-22 Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db Reporter: Cavan Loughran, Celvex Group Inc. Summary The /snippets/*filepath route handler serveSnippets in kernel/server/serve.go performs a bare filepath.Join(util.SnippetsPath, filePath) on the single-decoded c.Re
ghsa
CVE-2026-59834P3HIGH≥ 0, < 0.0.0-20260704035518-d0f0fe146fb02026-09-02
CVE-2026-59834 [HIGH] CWE-89 SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content ## Summary Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can reach `POST /api/search/fullTextSearchBlock`. An atta
ghsa
CVE-2026-74904P3HIGH≥ 0, < 0.0.0-20260804015139-bd067a4fe9b22026-10-02
CVE-2026-74904 [HIGH] CWE-204 SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRole
ghsa
CVE-2026-68587P3HIGHCVSS 8.6≥ 0, < 0.0.0-20260721013353-69db783b782a2026-09-03
CVE-2026-68587 [HIGH] CWE-862 SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check **CVE:** This vulnerability corresponds to [CVE-2026-68587](https://nvd.nist.gov/vuln/detail/CVE-2026-68587). ### Summar
ghsa
CVE-2026-72807P3HIGHCVSS 8.0≥ 0, < 0.0.0-20260723035036-0a176345e02a2026-09-03
CVE-2026-72807 [HIGH] CWE-1336 SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel **CVE:** This vulnerability corresponds to [CVE-2026-72807](https://nvd.nist.gov/vuln/detail/CVE-2026-72807). ### Summary Attribute-view (AV) template columns are liv
ghsa
CVE-2026-33670P3CRITICAL≥ 0, ≤ 0.0.0-20260317012524-fe4523fff2c82026-03-25
CVE-2026-33670 [CRITICAL] CWE-22 SiYuan has directory traversal within its publishing service SiYuan has directory traversal within its publishing service ### Details The /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. ### PoC ```python #!/usr/bin/env python3 """POC: SiYuan /api/file/readDir 未鉴权目录遍历""" import requests, json, sys def poc(target): base = target.rstrip("/") url = f"{base}/api/file/readDir" def read_dir(path, dept
ghsaosv
CVE-2026-23850P3HIGH≥ 0, < 0.0.0-20260118092326-b2274baba2e12026-01-21
CVE-2026-23850 [HIGH] CWE-22 SiYuan vulnerable to Arbitrary file Read / SSRF SiYuan vulnerable to Arbitrary file Read / SSRF ### Summary Markdown feature allows unrestricted server side html-rendering which allows arbitary file read (LFD) and fully SSRF access We in @0xL4ugh ( @abdoghazy2015, @xtromera, @A-z4ki, @ZeyadZonkorany and @KarimTantawey) During playing Null CTF 2025 that helps us solved a challenge with unintended way : ) Please note that we used the latest Version and deployed it vi
ghsaosv
CVE-2026-44670P3CRITICAL≥ 0, ≤ 0.0.0-20260421031503-96dfe0bea4742026-05-08
CVE-2026-44670 [CRITICAL] CWE-1188 SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE ## Summary The kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw `strings.ReplaceAll(tpl, "${avName}", nodeAvName)` to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (`render.ts:120` → `outerHTML
ghsa
CVE-2026-45375P3CRITICAL≥ 0, ≤ 0.0.0-20260421031503-96dfe0bea4742026-05-13
CVE-2026-45375 [CRITICAL] CWE-116 SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution ### Summary SiYuan's Bazaar (community marketplace) renders the `name` and `version` fields of a package's `plugin.json` (and the equivalent `theme.json` / `template.json` / `widget.json` / `icon.json`)
ghsa
CVE-2026-72801P3HIGHCVSS 7.5≥ 0, < 0.0.0-20260724102025-3bc014c7dc322026-09-03
CVE-2026-72801 [HIGH] CWE-522 SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking **CVE:** This vulnerability corresponds to [CVE-2026-72801](https://nvd.nist.gov/vuln/detail/CVE-2026-72801). ### Summary Two `CheckAuth`-only endpoints disclose the
ghsa
CVE-2024-55658P3HIGH≥ 0, ≤ 0.0.0-20241210012039-5129ad926a212024-12-11
CVE-2024-55658 [HIGH] CWE-22 SiYuan has an arbitrary file read and path traversal via /api/export/exportResources SiYuan has an arbitrary file read and path traversal via /api/export/exportResources ### Summary Siyuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. ### Impact Arbitrary File
ghsaosv
CVE-2026-25992P3HIGH≥ 0, ≤ 0.0.0-20260126094835-d5d10dd41b0c2026-01-28
CVE-2026-25992 [HIGH] CWE-178 SiYuan File Read API Case Sensitivity Bypass can Lead to Path Traversal SiYuan File Read API Case Sensitivity Bypass can Lead to Path Traversal # File Read Interface Case Bypass Vulnerability ## Vulnerability Name File Read Interface Case Bypass Vulnerability ## Overview The `/api/file/getFile` endpoint uses **case-sensitive string equality checks** to block access to sensitive files. On case-insensitive file systems such as **Windows**, attackers can bypass restr
ghsaosv
CVE-2026-33669P3CRITICAL≥ 0, ≤ 0.0.0-20260317012524-fe4523fff2c82026-03-25
CVE-2026-33669 [CRITICAL] CWE-125 SiYuan has Arbitrary Document Reading within the Publishing Service SiYuan has Arbitrary Document Reading within the Publishing Service ### Details Document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. ### PoC ```python #!/usr/bin/env python3 """SiYuan /api/block/getChildBlocks 文档内容读取""" import requests import json import sys def get_child_blocks(targe
ghsaosv
CVE-2026-45371P3HIGH≥ 0, < 0.0.0-20260512140701-d7b77d945e0d2026-05-13
CVE-2026-45371 [HIGH] CWE-285 SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs ### Summary SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs `POST /api/graph/getGraph`, `POST /api/graph/getLocalGraph`, `POST /api/sync/setSyncInterval`, `POST /api/storage/updateRecentDocViewTime`, `POST /api/storage/updateRecentDocCloseTime`, `POST /api/storage/updateRecentDocOpenTim
ghsa
CVE-2024-55657P3HIGH≥ 0, ≤ 0.0.0-20241210012039-5129ad926a212024-12-11
CVE-2024-55657 [HIGH] CWE-22 SiYuan has an arbitrary file read via /api/template/render SiYuan has an arbitrary file read via /api/template/render ### Summary An arbitrary file read vulnerability exists in Siyuan's /api/template/render endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system. ### Impact Arbitrary file read on the host
ghsaosv
CVE-2026-33203P3HIGH≥ 0, < 3.6.22026-03-18
CVE-2026-33203 [HIGH] CWE-248 SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass ## Summary The SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, p
ghsaosv
CVE-2026-32815P3MEDIUM≥ 0, ≤ 0.0.0-20260313024916-fd6526133bb32026-03-16
CVE-2026-32815 [MEDIUM] CWE-287 SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure # Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure ## Summary SiYuan's WebSocket endpoint (`/ws`) allows unauthenticated connections when specific URL parameters are provid
ghsaosv
Github.Com Siyuan-Note Siyuan Kernel vulnerabilities | cvebase