Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 4 of 11
CVE-2026-73041P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73041 [CRITICAL] CWE-79 CVE-2026-73041: SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
nvd
CVE-2026-74798P3HIGHCVSS 8.7fixed in 3.7.42026-08-17
CVE-2026-74798 [HIGH] CWE-22 CVE-2026-74798: SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool.
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join without validating that id matches SiYuan's node-ID format.
nvd
CVE-2026-93591P3HIGHCVSS 7.6fixed in 3.8.32026-09-18
CVE-2026-93591 [HIGH] CWE-89 CVE-2026-93591: SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt funct
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write
nvd
CVE-2026-59834P3HIGHCVSS 7.5fixed in 3.7.12026-07-09
CVE-2026-59834 [HIGH] CWE-89 CVE-2026-59834: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endp
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows from hidden documents by projec
nvd
CVE-2026-74904P3HIGHCVSS 7.5fixed in 3.7.42026-08-18
CVE-2026-74904 [HIGH] CWE-862 CVE-2026-74904: SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kerne
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access filtering, allowing anonymous publish-mode readers to disclose private block
nvd
CVE-2026-25539P3HIGHCVSS 7.2fixed in 3.5.52026-02-04
CVE-2026-25539 [HIGH] CWE-22 CVE-2026-25539: SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile end
SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or sh
nvd
CVE-2026-44670P3CRITICALCVSS 9.4fixed in 3.7.02026-05-14
CVE-2026-44670 [CRITICAL] CWE-79 CVE-2026-44670: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Att
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (render.
nvd
CVE-2026-45375P3CRITICALCVSS 9.0fixed in 3.7.02026-05-14
CVE-2026-45375 [CRITICAL] CWE-79 CVE-2026-45375: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (comm
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings → Marketplace UI without HTML escaping. The kernel-side helper sanitizePacka
nvd
CVE-2026-100639P3HIGHCVSS 8.8fixed in 3.8.42026-09-26
CVE-2026-100639 [HIGH] CWE-79 CVE-2026-100639: SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (
SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/pl
nvd
CVE-2026-33670P3HIGHCVSS 7.5fixed in 3.6.22026-03-26
CVE-2026-33670 [HIGH] CWE-22 CVE-2026-33670: SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir inte
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.
nvd
CVE-2026-23850P3HIGHCVSS 7.5fixed in 3.5.42026-01-19
CVE-2026-23850 [HIGH] CWE-22 CVE-2026-23850: SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature a
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.
nvd
CVE-2026-40322P3CRITICALCVSS 9.0fixed in 3.6.42026-04-16
CVE-2026-40322 [CRITICAL] CWE-79 CVE-2026-40322: SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered output. On desktop builds using
nvd
CVE-2026-72804P3HIGHCVSS 8.6fixed in 3.7.42026-08-12
CVE-2026-72804 [HIGH] CWE-200 CVE-2026-72804: SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph e
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.
nvd
CVE-2026-68586P3HIGHCVSS 8.6fixed in 3.7.32026-08-03
CVE-2026-68586 [HIGH] CWE-862 CVE-2026-68586: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionD
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including
nvd
CVE-2026-100637P3HIGHCVSS 7.6fixed in 3.8.42026-09-26
CVE-2026-100637 [HIGH] CWE-73 CVE-2026-100637: SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint th
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside
nvd
CVE-2026-100638P3HIGHCVSS 7.6fixed in 3.8.42026-09-26
CVE-2026-100638 [HIGH] CWE-73 CVE-2026-100638: SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write
nvd
CVE-2024-55658P3HIGHCVSS 7.5fixed in 3.1.162024-12-12
CVE-2024-55658 [HIGH] CWE-22 CVE-2024-55658: SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/expo
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 cont
nvd
CVE-2026-65605P3CRITICALCVSS 9.6fixed in 3.7.22026-07-23
CVE-2026-65605 [CRITICAL] CWE-79 CVE-2026-65605: SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (databas
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as are skipped by that check, a paylo
nvd
CVE-2026-73053P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73053 [CRITICAL] CWE-79 CVE-2026-73053: SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
nvd
CVE-2026-41421P3HIGHCVSS 8.8fixed in 3.6.52026-04-24
CVE-2026-41421 [HIGH] CWE-78 CVE-2026-41421: SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop render
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the frontend inserts it into the DOM with ins
nvd