Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 1 of 11
CVE-2026-69084P2CRITICALCVSS 10.0PoCfixed in 3.7.32026-08-03
CVE-2026-69084 [CRITICAL] CWE-89 CVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-su
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when
nvd
CVE-2026-69085P2CRITICALCVSS 10.0PoCfixed in 3.7.32026-08-03
CVE-2026-69085 [CRITICAL] CWE-89 CVE-2026-69085: SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Au
nvd
CVE-2026-33476P2HIGHCVSS 7.5PoCfixed in 3.6.22026-03-20
CVE-2026-33476 [HIGH] CWE-22 CVE-2026-33476: SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this e
nvd
CVE-2026-54069P2CRITICALCVSS 9.2PoCfixed in 3.7.02026-06-24
CVE-2026-54069 [CRITICAL] CWE-346 CVE-2026-54069: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without any authentication. Combined with the default empty AccessAuthCode on desktop installs, any Chrome/Chro
nvd
CVE-2026-34453P2HIGHCVSS 7.5PoCfixed in 3.6.22026-03-31
CVE-2026-34453 [HIGH] CWE-863 CVE-2026-34453: SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service expose
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess(nil, ...). Because the filter treats a nil context as
nvd
CVE-2026-66012P2CRITICALCVSS 10.0fixed in 3.7.22026-07-25
CVE-2026-66012 [CRITICAL] CWE-862 CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publi
nvd
CVE-2026-30869P2CRITICALCVSS 9.8fixed in 3.6.52026-03-10
CVE-2026-30869 [CRITICAL] CWE-22 CVE-2026-30869: SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in
SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive files such as conf/conf.json, which contains secrets including the API tok
nvd
CVE-2026-73056P2CRITICALCVSS 9.8fixed in 3.7.42026-08-16
CVE-2026-73056 [CRITICAL] CWE-307 CVE-2026-73056: SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mecha
nvd
CVE-2026-73046P2CRITICALCVSS 9.8fixed in 3.7.42026-08-15
CVE-2026-73046 [CRITICAL] CWE-307 CVE-2026-73046: SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure coun
nvd
CVE-2026-69083P2CRITICALCVSS 10.0fixed in 3.7.32026-08-03
CVE-2026-69083 [CRITICAL] CWE-89 CVE-2026-69083: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetConten
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook dat
nvd
CVE-2026-32767P2CRITICALCVSS 9.8fixed in 3.8.22026-03-20
CVE-2026-32767 [CRITICAL] CWE-89 CVE-2026-32767: SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization
SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. When the method parameter is set to 2, the endpoint passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without any authorization or read-on
nvd
CVE-2026-72811P2CRITICALCVSS 10.0fixed in 3.7.42026-08-14
CVE-2026-72811 [CRITICAL] CWE-89 CVE-2026-72811: SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A singl
nvd
CVE-2026-54067P2CRITICALCVSS 9.9fixed in 3.7.02026-06-24
CVE-2026-54067 [CRITICAL] CWE-79 CVE-2026-54067: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body cont
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing breaks out of its surrounding tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer runs with nodeIntegration:true, so require('child_
nvd
CVE-2026-29183P3MEDIUMCVSS 6.1PoCfixed in 3.6.12026-03-06
CVE-2026-29183 [MEDIUM] CWE-79 CVE-2026-29183: SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflect
SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when type=8, attacker-controlled content is embedded into SVG output without escaping. Because the endpoint is unauthenticated and returns image/svg+xml, a craf
nvd
CVE-2026-34449P2CRITICALCVSS 9.6fixed in 3.6.22026-03-31
CVE-2026-34449 [CRITICAL] CWE-942 CVE-2026-34449: SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can ac
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet e
nvd
CVE-2026-54158P2CRITICALCVSS 9.9fixed in 3.7.02026-06-24
CVE-2026-54158 [CRITICAL] CWE-79 CVE-2026-54158: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (d
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like or "> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the victim opens t
nvd
CVE-2026-34605P3MEDIUMCVSS 6.1PoCv>= 3.6.0, < 3.6.22026-03-31
CVE-2026-34605 [MEDIUM] CWE-79 CVE-2026-34605: SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the Sa
SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-prefixed element names such as . The Go HTML5 parser records the element's tag as "x:script" rather th
nvd
CVE-2024-55660P3CRITICALCVSS 9.8fixed in 3.7.42024-12-12
CVE-2024-55660 [CRITICAL] CWE-1336 CVE-2024-55660: SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/r
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.
nvd
CVE-2026-77086P3CRITICALCVSS 9.1fixed in 3.7.42026-08-21
CVE-2026-77086 [CRITICAL] CWE-22 CVE-2026-77086: SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall end
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall op
nvd
CVE-2025-21609P3CRITICALCVSS 9.1v= 3.1.182025-01-03
CVE-2025-21609 [CRITICAL] CWE-459 CVE-2025-21609: SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.1
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the ser
nvd
1 / 11Next →