Github.Com Siyuan-Note Siyuan Kernel vulnerabilities
94 known vulnerabilities affecting github.com/siyuan-note_siyuan_kernel.
Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH38MEDIUM33LOW2
Vulnerabilities
Page 4 of 5
CVE-2026-23851P3HIGH≥ 0, < 0.0.0-20260118092521-f8f4b517077b2026-01-21
CVE-2026-23851 [HIGH] CWE-22 SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality
SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality
### Summary
The SiYuan Note application (v3.5.3) contains a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authenticated users to copy files from any location on the server's filesystem into the application's workspace without proper path validation
### Details
The vulnerability exists in the ap
ghsaosv
CVE-2026-34585P3HIGH≥ 0, < 0.0.0-20260329142331-918d1bd9f9672026-04-01
CVE-2026-34585 [HIGH] CWE-79 SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
### Summary
A vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a `.sy` document, package it as a `.sy.zip`, and have the victim impor
ghsaosv
CVE-2026-30926P3HIGH≥ 0, ≤ 0.0.0-20260304035530-d03ebdec82792026-03-09
CVE-2026-30926 [HIGH] CWE-284 SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildren
SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildren
### Summary
A privilege escalation vulnerability exists in the publish service of SiYuan Note that allows a low-privilege publish account (RoleReader) to modify notebook content via the `/api/block/appendHeadingChil
ghsaosv
CVE-2026-32704P3MEDIUM≥ 0, < 3.6.12026-03-13
CVE-2026-32704 [MEDIUM] CWE-285 SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
### Summary
`POST /api/template/renderSprig` lacks `model.CheckAdminRole`, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes.
### Details
**File:** `kernel/api/
ghsaosv
CVE-2026-74802P3LOW≥ 0, < 0.0.0-20260803045322-cb67e0b4fab52026-10-02
CVE-2026-74802 [LOW] CWE-346 SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
**High**
## Package
gomod `github.com/siyuan-note/siyuan/kernel`
## Affected versions
3.7.3
## Patched versions
*(none yet — leave blank until a fix is released)*
## Description
###
ghsa
CVE-2026-72812P3MEDIUMCVSS 6.5≥ 0, < 0.0.0-20260723002528-7d273c271ce12026-09-03
CVE-2026-72812 [MEDIUM] CWE-862 SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
**CVE:** This vulnerability corresponds to [CVE-2026-72812](https://nvd.nist.gov/vuln/detail/CVE-2026-72812).
### Summar
ghsa
CVE-2026-72806P3MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260723040913-768427f20f132026-09-03
CVE-2026-72806 [MEDIUM] CWE-862 SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
**CVE:** This vulnerability corresponds to [CVE-2026-72806](https://nvd.nist.gov/vuln/detail/CVE-2026-72806).
### Summary
`Filt
ghsa
CVE-2026-32938P3CRITICAL≥ 0, ≤ 0.0.0-20260313024916-fd6526133bb32026-03-17
CVE-2026-32938 [CRITICAL] CWE-200 SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service
SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service
### Summary
In SiYuan, `/api/lute/html2BlockDOM` on the desktop copies local files pointed to by `file://` links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list. Together with `GET /assets/*path`, which only requires authentication, a publish-service visitor can cause t
ghsaosv
CVE-2026-72796P3MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260725122641-34be6c0bb0732026-09-04
CVE-2026-72796 [MEDIUM] CWE-862 SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
**CVE:** This vulnerability corresponds to [CVE-2026-72796](https://nvd.nist.gov/vuln/detail/CVE-2026-72796).
### Summary
Several static-file route
ghsa
CVE-2026-54068P3MEDIUM≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54068 [MEDIUM] CWE-306 SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
### Summary
The `/api/icon/getDynamicIcon` endpoint is explicitly excluded from authentication in SiYuan's kernel router (`router.go`, "不需要鉴权" -- no auth needed). When called with `type=8` and a valid block `id` parameter, this endpoint invokes `RenderDynamicIconCon
ghsa
CVE-2026-54070P3HIGH≥ 0, < 0.0.0-20260628153353-2d5d72223df42026-07-10
CVE-2026-54070 [HIGH] CWE-184 SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
## Summary
`renderPackageREADME` in `kernel/bazaar/readme.go` renders a Bazaar package README from Markdown to HTML with the lute engine and `SetSanitize(true)`. The lute sanitizer is an event-handler blocklist: `allowAttr` rejects only attribute names present in a fixed `eventAttrs` map copied from the w3schools leg
ghsa
CVE-2026-72800P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260724103335-f36331956ae92026-09-03
CVE-2026-72800 [MEDIUM] CWE-862 SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
**CVE:** This vulnerability corresponds to [CVE-2026-72800](https://nvd.nist.gov/vuln/detail/CVE-2026-72800).
### Summary
`POST /api/av/getAt
ghsa
CVE-2026-33194P3MEDIUM≥ 0, < 3.6.22026-03-18
CVE-2026-33194 [MEDIUM] CWE-22 SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home (GHSA-h5vh-m7fg-w5h6 Bypass)
SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home (GHSA-h5vh-m7fg-w5h6 Bypass)
## Summary
The `IsSensitivePath()` function in `kernel/util/path.go` uses a denylist approach that was recently expanded (GHSA-h5vh-m7fg-w5h6, commit 9914fd1) but remains incomplete. Multiple security-relevant Lin
ghsaosv
CVE-2026-40107P3HIGH≥ 0, < 0.0.0-20260407035653-2f416e5253f12026-04-10
CVE-2026-40107 [HIGH] CWE-918 SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
SiYuan configures Mermaid.js with `securityLevel: "loose"` and `htmlLabels: true`. In this mode, `` tags with `src` attributes survive Mermaid's internal DOMPurify and land in SVG `` blocks. The SVG is injected via `innerHTML` with no secondary sanitization. When a victim opens a note c
ghsa
CVE-2026-73605P3MEDIUM≥ 0, < 0.0.0-20260812083335-251596fc0de22026-10-01
CVE-2026-73605 [MEDIUM] CWE-862 SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
### Summary
`/api/file/getUniqueFilename` takes a path from the request body and passes it to a filesystem existence check with no valid
ghsa
CVE-2026-72808P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260723031702-509b350559402026-09-03
CVE-2026-72808 [MEDIUM] CWE-862 SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
**CVE:** This vulnerability corresponds to [CVE-2026-72808](https://nvd.nist.gov/vuln/detail/CVE-2026-72808).
### Summary
The `/api/asset/getFileAnnotation` endpoint returns the conte
ghsa
CVE-2026-72799P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260724112156-5bae0926b8962026-09-04
CVE-2026-72799 [MEDIUM] CWE-862 SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
**CVE:** This vulnerability corresponds to [CVE-2026-72799](https://nvd.nist.gov/vuln/detail/CVE-2026-72799).
### Summary
Five filetree endpoints resolve arbitrary document IDs and paths with no pu
ghsa
CVE-2026-72803P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260724093256-229fdffd7e4a2026-09-03
CVE-2026-72803 [MEDIUM] CWE-862 SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
**CVE:** This vulnerability corresponds to [CVE-2026-72803](https://nvd.nist.gov/vuln/detail/CVE-2026-72803).
### Summary
`POST /api/attr/g
ghsa
CVE-2026-68585P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260721014951-ffde3b21eca42026-09-03
CVE-2026-68585 [MEDIUM] CWE-862 SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
**CVE:** This vulnerability corresponds to [CVE-2026-68585](https://nvd.nist.gov/vuln/detail/CVE-2026-68585).
##
ghsa
CVE-2026-72790P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260726005141-9edb321eb4512026-09-08
CVE-2026-72790 [MEDIUM] CWE-862 SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
**CVE:** This vulnerability corresponds to [CVE-2026-72790](https://nvd.nist.gov/vuln/detail/CVE-2026-72790).
### Relationship to GHSA-8x8
ghsa