Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 2 of 11
CVE-2026-73043P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73043 [CRITICAL] CWE-79 CVE-2026-73043: SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration en
nvd
CVE-2025-67488P3HIGHCVSS 8.8≤ 0.0.0-20251202123337-6ef83b42c7ce2025-12-09
CVE-2025-67488 [HIGH] CWE-22 CVE-2025-67488: SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-2025120212
SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the system. An authenticated user with access to the import functionality in notes is able to overwrite any fil
nvd
CVE-2026-72794P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72794 [HIGH] CWE-522 CVE-2026-72794: siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.
nvd
CVE-2026-74799P3CRITICALCVSS 9.3fixed in 3.7.42026-08-17
CVE-2026-74799 [CRITICAL] CWE-215 CVE-2026-74799: SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
nvd
CVE-2026-32751P3CRITICALCVSS 9.0fixed in 3.6.12026-03-19
CVE-2026-32751 [CRITICAL] CWE-79 CVE-2026-32751: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket events. The desktop version (Files.ts) properly uses escapeHtml() for the same operation. An authenticated user who can rename noteboo
nvd
CVE-2026-33066P3CRITICALCVSS 9.0fixed in 3.6.42026-03-20
CVE-2026-33066 [CRITICAL] CWE-79 CVE-2026-33066: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREA
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through unmodified. The frontend then assigns the rendered HTML to innerHTML without any additional sanitization. A malicious package autho
nvd
CVE-2026-85174P3HIGHCVSS 8.8fixed in 3.8.22026-09-03
CVE-2026-85174 [HIGH] CWE-532 CVE-2026-85174: SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file wh
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
nvd
CVE-2026-29073P3HIGHCVSS 8.8fixed in 3.6.02026-03-06
CVE-2026-29073 [HIGH] CWE-89 CVE-2026-29073: SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a
SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin rights, any logged-in user, even readers, can run any sql query on the database. This issue has been patched in version 3.6.0.
nvd
CVE-2026-68584P3HIGHCVSS 8.6fixed in 3.7.32026-08-03
CVE-2026-68584 [HIGH] CWE-288 CVE-2026-68584: SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where c
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtai
nvd
CVE-2026-32110P3HIGHCVSS 8.3fixed in 3.6.02026-03-11
CVE-2026-32110 [HIGH] CWE-918 CVE-2026-32110: SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endp
SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requests from the server. The endpoint accepts a user-controlled URL and makes HTTP requests to it, returning the full response body and headers. There is no URL validation to prevent requests to in
nvd
CVE-2026-50551P3CRITICALCVSS 9.9fixed in 3.7.02026-06-24
CVE-2026-50551 [CRITICAL] CWE-79 CVE-2026-50551: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a sto
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.
nvd
CVE-2026-73054P3HIGHCVSS 7.5fixed in 3.7.42026-08-15
CVE-2026-73054 [HIGH] CWE-287 CVE-2026-73054: SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoi
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation an
nvd
CVE-2026-39846P3CRITICALCVSS 9.0fixed in 3.6.42026-04-07
CVE-2026-39846 [CRITICAL] CWE-79 CVE-2026-39846: SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop render
nvd
CVE-2026-86712P3HIGHCVSS 8.8fixed in 3.8.22026-09-08
CVE-2026-86712 [HIGH] CWE-79 CVE-2026-86712: SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitizat
SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electr
nvd
CVE-2026-72810P3HIGHCVSS 8.6fixed in 3.7.42026-08-14
CVE-2026-72810 [HIGH] CWE-862 CVE-2026-72810: SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authen
nvd
CVE-2026-72789P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72789 [HIGH] CWE-862 CVE-2026-72789: SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating the
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
nvd
CVE-2026-73045P3HIGHCVSS 7.5fixed in 3.7.42026-08-15
CVE-2026-73045 [HIGH] CWE-307 CVE-2026-73045: SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerabil
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected publishe
nvd
CVE-2026-23852P3CRITICALCVSS 9.6fixed in 3.5.42026-01-19
CVE-2026-23852 [CRITICAL] CWE-94 CVE-2026-23852: SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site S
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is later rendered in the dynamic icon feature in an unsanitized context,
nvd
CVE-2026-44588P3CRITICALCVSS 9.4fixed in 3.7.02026-05-14
CVE-2026-44588 [CRITICAL] CWE-79 CVE-2026-44588: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in app/src/dialog/tooltip.ts:41. The encoder used at the producer side, escapeAriaLabel in app/
nvd
CVE-2026-32749P3CRITICALCVSS 9.1fixed in 3.6.12026-03-19
CVE-2026-32749 [CRITICAL] CWE-22 CVE-2026-32749: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/impo
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the temp directory - including system paths that e
nvd