Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 3 of 11
CVE-2026-92986P3HIGHCVSS 8.8fixed in 3.8.42026-09-17
CVE-2026-92986 [HIGH] CWE-79 CVE-2026-92986: SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping marku
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
nvd
CVE-2026-92985P3HIGHCVSS 8.8fixed in 3.8.42026-09-17
CVE-2026-92985 [HIGH] CWE-79 CVE-2026-92985: SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when render
SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.
nvd
CVE-2026-87815P3HIGHCVSS 8.7fixed in 3.8.22026-09-09
CVE-2026-87815 [HIGH] CWE-73 CVE-2026-87815: SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
nvd
CVE-2026-40318P3HIGHCVSS 8.5fixed in 3.6.42026-04-16
CVE-2026-40318 [HIGH] CWE-24 CVE-2026-40318: SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intend
nvd
CVE-2026-72809P3HIGHCVSS 8.0fixed in 3.7.42026-08-12
CVE-2026-72809 [HIGH] CWE-290 CVE-2026-72809: SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints (including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export
nvd
CVE-2026-100644P3HIGHCVSS 7.5fixed in 3.8.42026-09-26
CVE-2026-100644 [HIGH] CWE-89 CVE-2026-100644: SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the da
SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.
nvd
CVE-2026-33067P3CRITICALCVSS 9.0fixed in 3.6.12026-03-20
CVE-2026-33067 [CRITICAL] CWE-79 CVE-2026-33067: SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata f
SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject arbitrary HTML/JavaScript into these fields, which executes automatically when any user browses the Bazaar page. Because SiYuan's El
nvd
CVE-2026-73052P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73052 [CRITICAL] CWE-79 CVE-2026-73052: SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code exe
nvd
CVE-2026-85175P3HIGHCVSS 8.8fixed in 3.8.22026-09-03
CVE-2026-85175 [HIGH] CWE-552 CVE-2026-85175: SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the b
nvd
CVE-2026-73608P3HIGHCVSS 8.6fixed in 3.7.42026-08-13
CVE-2026-73608 [HIGH] CWE-862 CVE-2026-73608: SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or maste
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs no authorization checks (no CheckReadonly, no publish-access or encrypted
nvd
CVE-2026-100641P3HIGHCVSS 8.0fixed in 3.8.42026-09-26
CVE-2026-100641 [HIGH] CWE-79 CVE-2026-100641: SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it int
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as becomes an executable event-handler attribute.
nvd
CVE-2026-74868P3HIGHCVSS 7.5fixed in 3.7.42026-08-17
CVE-2026-74868 [HIGH] CWE-307 CVE-2026-74868: SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a separate, unauthenticated-by-default listener (default TCP port 6808) and gates named publish-viewer accounts (Conf.Publish
nvd
CVE-2026-34448P3CRITICALCVSS 9.0fixed in 3.6.22026-03-31
CVE-2026-34448 [CRITICAL] CWE-79 CVE-2026-34448: SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without extensions as images, stores th
nvd
CVE-2026-73042P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73042 [CRITICAL] CWE-79 CVE-2026-73042: SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins d
nvd
CVE-2026-60084P3HIGHCVSS 8.7fixed in 3.7.42026-08-22
CVE-2026-60084 [HIGH] CWE-22 CVE-2026-60084: SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/re
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively delete any file or directory the kernel process has permission to remove,
nvd
CVE-2026-54759P3HIGHCVSS 8.7fixed in 3.7.02026-06-24
CVE-2026-54759 [HIGH] CWE-79 CVE-2026-54759: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove elements. Combined with the SiYuan Electron client's permissive security configuration, an attacker can include a malicious in a Bazaar package README that executes arbitrary commands on the victim's machine when the package details are
nvd
CVE-2026-72798P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72798 [HIGH] CWE-862 CVE-2026-72798: SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeVie
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering e
nvd
CVE-2026-72793P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72793 [HIGH] CWE-522 CVE-2026-72793: SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances
nvd
CVE-2026-72795P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72795 [HIGH] CWE-862 CVE-2026-72795: SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBloc
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
nvd
CVE-2026-40259P3HIGHCVSS 8.1fixed in 0.0.0-20260407035653-2f416e5253f1fixed in 3.6.42026-04-16
CVE-2026-40259 [HIGH] CWE-285 CVE-2026-40259: SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service RoleReader tokens. The handler passes a caller-controlled id directly to a model function that unconditionally deletes the corresponding attr
nvd