cbcvebase.

Siyuan-Note Siyuan vulnerabilities

201 known vulnerabilities affecting siyuan-note/siyuan.

Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70

Vulnerabilities

Page 10 of 11
CVE-2026-59809P4MEDIUMCVSS 4.9fixed in 3.8.02026-08-22
CVE-2026-59809 [MEDIUM] CWE-201 CVE-2026-59809: SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.
nvd
CVE-2024-55659P4MEDIUMCVSS 5.4fixed in 3.1.162024-12-12
CVE-2024-55659 [MEDIUM] CWE-22 CVE-2024-55659: SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` e SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored cross-site scripting (via the file write). Version 3.1.16 contains a patch for the issue.
nvd
CVE-2026-72802P4MEDIUMCVSS 5.3fixed in 3.7.42026-08-12
CVE-2026-72802 [MEDIUM] CWE-639 CVE-2026-72802: SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPat SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing
nvd
CVE-2026-105205P4MEDIUMCVSS 5.3fixed in 3.8.52026-10-04
CVE-2026-105205 [MEDIUM] CWE-200 CVE-2026-105205: SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode reader SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtai
nvd
CVE-2026-60083P4MEDIUMCVSS 4.9fixed in 3.8.02026-08-22
CVE-2026-60083 [MEDIUM] CWE-863 CVE-2026-60083: SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails t SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippet
nvd
CVE-2026-82649P4HIGHCVSS 7.0≥ 2.0.14, < 3.8.12026-08-30
CVE-2026-82649 [HIGH] CWE-427 CVE-2026-82649: SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that includes the installer's own launch
nvd
CVE-2026-23847P4MEDIUMCVSS 6.1fixed in 3.5.42026-01-19
CVE-2026-23847 [MEDIUM] CWE-79 CVE-2026-23847: SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflecte SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIcon due to unsanitized SVG input. The endpoint generates SVG images for text icons (type=8). The content query parameter is inserted directly into the SVG tag without XML escaping. Since the response Conte
nvd
CVE-2026-82652P4MEDIUMCVSS 5.3fixed in 3.8.12026-08-30
CVE-2026-82652 [MEDIUM] CWE-668 CVE-2026-82652: SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view ke SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
nvd
CVE-2026-62204P4MEDIUMCVSS 6.6fixed in 3.7.42026-08-22
CVE-2026-62204 [MEDIUM] CWE-345 CVE-2026-62204: SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package conte SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.
nvd
CVE-2026-23645P4MEDIUMCVSS 6.1fixed in 3.5.4-dev22026-01-16
CVE-2026-23645 [MEDIUM] CWE-79 CVE-2026-23645: SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a St SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views a malicious SVG file (e.g., imported from an untrusted source), arbitrary JavaScript code is executed
nvd
CVE-2026-25647P4MEDIUMCVSS 5.4fixed in 3.5.52026-02-06
CVE-2026-25647 [MEDIUM] CWE-79 CVE-2026-25647: Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used i Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript into a Markdown text/note. When another user clicks the rendered content, the script executes in the co
nvd
CVE-2026-74903P4MEDIUMCVSS 4.3fixed in 3.7.42026-08-18
CVE-2026-74903 [MEDIUM] CWE-400 CVE-2026-74903: SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBloc SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which is guarded only by CheckAuth middleware instead of CheckAdminRole like its sibling endpoint. Authenticated users with RoleEditor or RoleReader roles can invoke the endpoint to transform arbitrary DOM input, and large payloads caus
nvd
CVE-2026-100640P4MEDIUMCVSS 4.7fixed in 3.8.42026-09-26
CVE-2026-100640 [MEDIUM] CWE-200 CVE-2026-100640: SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows re SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office by
nvd
CVE-2026-82650P4MEDIUMCVSS 4.4fixed in 3.8.12026-08-30
CVE-2026-82650 [MEDIUM] CWE-668 CVE-2026-82650: SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace directory (util.IsAbsPathInWorkspace) but, unlike the file API's refuse
nvd
CVE-2026-93921P4MEDIUMCVSS 4.3≤ 3.8.42026-09-19
CVE-2026-93921 [MEDIUM] CWE-862 CVE-2026-93921: SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and hierarchical paths of restricted documents via template injection.
nvd
CVE-2026-100634P4MEDIUMCVSS 4.7fixed in 3.8.42026-09-26
CVE-2026-100634 [MEDIUM] CWE-862 CVE-2026-100634: SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened works
nvd
CVE-2026-45148P4MEDIUMCVSS 4.3fixed in 3.7.02026-05-14
CVE-2026-45148 [MEDIUM] CWE-863 CVE-2026-45148: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This vulnerability is fixed in 3.7.0.
nvd
CVE-2026-45147P4MEDIUMCVSS 4.3fixed in 3.7.02026-05-14
CVE-2026-45147 [MEDIUM] CWE-285 CVE-2026-45147: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded by both. Any authenticated user — including publish-service RoleReader ac
nvd
CVE-2026-86191P4MEDIUMCVSS 4.3fixed in 3.8.22026-09-05
CVE-2026-86191 [MEDIUM] CWE-639 CVE-2026-86191: SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeVie SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and rel
nvd
CVE-2026-85579P4MEDIUMCVSS 4.3fixed in 3.8.22026-09-04
CVE-2026-85579 [MEDIUM] CWE-639 CVE-2026-85579: SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated r
nvd
Siyuan-Note Siyuan vulnerabilities | cvebase