cbcvebase.

Github.Com Siyuan-Note Siyuan Kernel vulnerabilities

94 known vulnerabilities affecting github.com/siyuan-note_siyuan_kernel.

Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH38MEDIUM33LOW2

Vulnerabilities

Page 5 of 5
CVE-2026-72797P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260724123622-8fb1b57660932026-09-04
CVE-2026-72797 [MEDIUM] CWE-862 SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers **CVE:** This vulnerability corresponds to [CVE-2026-72797](https://nvd.nist.gov/vuln/detail/CVE-2026-72797). ### Summary `POST /api/notebook/getEncryptedNotebookStatus` returns the identifier, name, and cur
ghsa
CVE-2026-72792P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260726002639-4515fa257cfa2026-09-04
CVE-2026-72792 [MEDIUM] CWE-863 SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password **CVE:** This vulnerability corresponds to [CVE-2026-72792](https://nvd.nist.gov/vuln/detail/CVE-2026-72792). ### Summary `/api/tag/getTag` filters its results for reader roles through `FilterTagsByPublishIgnore`, which checks only the *visibl
ghsa
CVE-2026-72805P4MEDIUMCVSS 5.8≥ 0, < 0.0.0-20260723163028-931ba693375e2026-09-03
CVE-2026-72805 [MEDIUM] CWE-862 SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents **CVE:** This vulnerability corresponds to [CVE-2026-72805](https://nvd.nist.gov/vuln/detail/CVE-2026-72805). ### Summary Three block endpoints retur
ghsa
CVE-2026-72788P4MEDIUM≥ 0, < 0.0.0-20260812083335-251596fc0de22026-10-01
CVE-2026-72788 [MEDIUM] CWE-863 SiYuan discloses an administrator's open documents and search terms to anonymous readers SiYuan discloses an administrator's open documents and search terms to anonymous readers ### Summary `/api/system/getConf` serves `Conf.UILayout` to publish readers after passing it through `FilterConfByPublishIgnore`, whose only function is to filter that layout. The layout is written exclusively by `setUILayout`, which is administrator-gated, so what readers receive is the
ghsa
CVE-2026-73607P4MEDIUM≥ 0, < 0.0.0-20260812083335-251596fc0de22026-10-01
CVE-2026-73607 [MEDIUM] CWE-862 SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check ### Summary `/api/storage/getOutlineStorage` is registered with `CheckAuth` only and performs no authorization of any kind. Given a document identifier it returns that
ghsa
CVE-2026-72802P4MEDIUMCVSS 5.3≥ 0, < 0.0.0-20260724095509-eee3410aa1312026-09-03
CVE-2026-72802 [MEDIUM] CWE-639 SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath **CVE:** This vulnerability corresponds to [CVE-2026-72802](https://nvd.nist.gov/vuln/detail/CVE-2026-72802). ### Summary `POST /api/asset/resolveAssetPath` returns the resolved **absolute** filesystem path of an asset, unmodified. The route is `CheckAuth`-only, so it is reachable by the publish `RoleR
ghsa
CVE-2026-73606P4MEDIUM≥ 0, < 0.0.0-20260812083335-251596fc0de22026-10-01
CVE-2026-73606 [MEDIUM] CWE-863 SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block ### Summary `/api/block/getRefIDs` filters its results for reader roles through a helper that checks only the visibility tiers. The password tier is not
ghsa
CVE-2026-73609P4MEDIUM≥ 0, < 0.0.0-20260812083335-251596fc0de22026-10-01
CVE-2026-73609 [MEDIUM] CWE-862 SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering ### Summary `/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label
ghsa
CVE-2026-32747P4MEDIUM≥ 0, ≤ 0.0.0-20260313024916-fd6526133bb32026-03-16
CVE-2026-32747 [MEDIUM] CWE-184 SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secrets SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secrets ### Summary POST /api/file/globalCopyFiles reads source files using filepath.Abs() with no workspace boundary check, relying solely on util.IsSensitivePath() whose blocklist omits /proc/, /run/secrets/, and home directory dotfiles. An admin can copy /proc/1/environ o
ghsaosv
CVE-2024-55659P4HIGH≥ 0, ≤ 0.0.0-20241210012039-5129ad926a212024-12-11
CVE-2024-55659 [HIGH] CWE-22 SiYuan has an arbitrary file write in the host via /api/asset/upload SiYuan has an arbitrary file write in the host via /api/asset/upload ### Summary The /api/asset/upload endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored XSS (via the file write). ### Impact Arbitrary file write
ghsaosv
CVE-2026-23847P4LOW≥ 0, < 0.0.0-20260118021606-5c0cc375b4752026-01-21
CVE-2026-23847 [LOW] CWE-79 SiYuan has a Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon SiYuan has a Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon ### Summary Reflected XSS in /api/icon/getDynamicIcon due to unsanitized SVG input. ### Details The endpoint generates SVG images for text icons (type=8). The content query parameter is inserted directly into the SVG tag without XML escaping. Since the response Content-Type is image/svg+xml, injecting unescaped
ghsaosv
CVE-2026-23645P4MEDIUM≥ 0, < 0.0.0-20260116101155-11115da3d0de2026-01-16
CVE-2026-23645 [MEDIUM] CWE-79 SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File Upload SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File Upload ### Summary A Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views a malicious SVG file (e.g., imported from an untrusted source), arbitrary JavaScript code is executed in the cont
ghsaosv
CVE-2026-45148P4MEDIUM≥ 0, < 0.0.0-20260512140701-d7b77d945e0d2026-05-13
CVE-2026-45148 [MEDIUM] CWE-863 SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode ### Summary The advisory `GHSA-c77m-r996-jr3q` patched `getBookmark` so that, when invoked by a publish-mode `RoleReader`, results are filtered through `FilterBlocksByPublishAccess` to remove entries from password-protected / publish-ig
ghsa
CVE-2026-45147P4MEDIUM≥ 0, < 0.0.0-20260512140701-d7b77d945e0d2026-05-13
CVE-2026-45147 [MEDIUM] CWE-285 SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk ### Summary `POST /api/tag/getTag` is registered with `model.CheckAuth` only, omitting both `model.CheckAdminRole` and `model.CheckReadonly`, despite the handler performing a configuration write that is normally guarded by both. Any authentic
ghsa
Github.Com Siyuan-Note Siyuan Kernel vulnerabilities | cvebase