Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 5 of 11
CVE-2026-100646P3HIGHCVSS 8.1fixed in 3.8.42026-09-26
CVE-2026-100646 [HIGH] CWE-346 CVE-2026-100646: SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3,
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carr
nvd
CVE-2026-69086P3HIGHCVSS 7.7fixed in 3.7.32026-08-03
CVE-2026-69086 [HIGH] CWE-22 CVE-2026-69086: SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute
nvd
CVE-2026-25992P3HIGHCVSS 7.5fixed in 3.5.52026-02-10
CVE-2026-25992 [HIGH] CWE-22 CVE-2026-25992: SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint use
SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files. On case-insensitive file systems such as Windows, attackers can bypass restrictions using mixed-case paths and read protected configuration files. This vulnerability is fixed in
nvd
CVE-2026-33669P3HIGHCVSS 7.5fixed in 3.6.22026-03-26
CVE-2026-33669 [HIGH] CWE-125 CVE-2026-33669: SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieve
SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.
nvd
CVE-2026-104410P3HIGHCVSS 7.5fixed in 3.8.52026-10-02
CVE-2026-104410 [HIGH] CWE-862 CVE-2026-104410: SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.
nvd
CVE-2026-45371P3HIGHCVSS 7.2fixed in 3.7.02026-05-14
CVE-2026-45371 [HIGH] CWE-285 CVE-2026-45371: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode R
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST /api/storage/updateRecentDocCloseTime, POST /api/storage/upd
nvd
CVE-2026-68587P3HIGHCVSS 8.6fixed in 3.7.32026-08-03
CVE-2026-68587 [HIGH] CWE-862 CVE-2026-68587: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDelet
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content
nvd
CVE-2026-72807P3HIGHCVSS 8.0fixed in 3.7.42026-08-12
CVE-2026-72807 [HIGH] CWE-89 CVE-2026-72807: SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view t
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary
nvd
CVE-2026-59832P3HIGHCVSS 7.7fixed in 3.7.12026-07-09
CVE-2026-59832 [HIGH] CWE-22 CVE-2026-59832: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepa
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as /snippets/%2e%2e/%2e%2e/conf/conf.jso
nvd
CVE-2026-87807P3HIGHCVSS 7.5fixed in 3.8.22026-09-09
CVE-2026-87807 [HIGH] CWE-89 CVE-2026-87807: siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSe
siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes.
nvd
CVE-2026-65606P3CRITICALCVSS 9.6fixed in 3.7.22026-07-23
CVE-2026-65606 [CRITICAL] CWE-79 CVE-2026-65606: SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing inject
nvd
CVE-2026-74800P3CRITICALCVSS 9.0fixed in 3.7.42026-08-17
CVE-2026-74800 [CRITICAL] CWE-79 CVE-2026-74800: SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
nvd
CVE-2026-59855P3HIGHCVSS 8.6fixed in 3.7.12026-07-09
CVE-2026-59855 [HIGH] CWE-80 CVE-2026-59855: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/s
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src attribute, inject an event handler, and execute JavaScript that can run OS com
nvd
CVE-2025-68948P3HIGHCVSS 8.1≤ 3.5.12025-12-27
CVE-2025-68948 [HIGH] CWE-321 CVE-2025-68948: SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and pri
SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is stored within the session cookie, an attacker who int
nvd
CVE-2024-55657P3HIGHCVSS 7.5fixed in 3.1.162024-12-12
CVE-2024-55657 [HIGH] CWE-22 CVE-2024-55657: SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vu
SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system. Version 3.1.16 contains a patch for the issue.
nvd
CVE-2026-33203P3HIGHCVSS 7.5fixed in 3.6.22026-03-20
CVE-2026-33203 [HIGH] CWE-248 CVE-2026-33203: SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocke
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when a specific "auth keepalive" query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed me
nvd
CVE-2026-32815P3HIGHCVSS 7.5fixed in 3.6.12026-03-19
CVE-2026-32815 [HIGH] CWE-287 CVE-2026-32815: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoin
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unauthenticated connections when specific URL parameters are provided (?app=siyuan&id=auth&type=auth). This bypass, intended for the login page to keep the kernel alive, allows any external client — including malicious websites via cross-
nvd
CVE-2026-72801P3HIGHCVSS 7.5fixed in 3.7.42026-08-12
CVE-2026-72801 [HIGH] CWE-522 CVE-2026-72801: SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data k
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
nvd
CVE-2026-73044P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73044 [CRITICAL] CWE-79 CVE-2026-73044: SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electro
nvd
CVE-2026-93922P3HIGHCVSS 8.8≤ 3.8.42026-09-19
CVE-2026-93922 [HIGH] CWE-79 CVE-2026-93922: SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without esca
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
nvd