cbcvebase.

Siyuan-Note Siyuan vulnerabilities

201 known vulnerabilities affecting siyuan-note/siyuan.

Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70

Vulnerabilities

Page 7 of 11
CVE-2026-41894P3HIGHCVSS 7.1fixed in 3.7.02026-04-24
CVE-2026-41894 [HIGH] CWE-22 CVE-2026-41894: SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026- SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause — a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use double URL encoding (%252e%252e) to traverse directories and read arbitrary w
nvd
CVE-2026-74905P3HIGHCVSS 7.1fixed in 3.7.42026-08-18
CVE-2026-74905 [HIGH] CWE-918 CVE-2026-74905: SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. The function only checks for loopback, link-local unicast, private, and unspecified addresses and does not recognize IPv6 transition addresses (NAT64 64:ff9b::
nvd
CVE-2026-93923P3HIGHCVSS 8.8≤ 3.8.42026-09-19
CVE-2026-93923 [HIGH] CWE-79 CVE-2026-93923: SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark do SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.
nvd
CVE-2026-73050P3CRITICALCVSS 9.0fixed in 3.7.42026-08-15
CVE-2026-73050 [CRITICAL] CWE-79 CVE-2026-73050: SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the mali
nvd
CVE-2026-85583P3MEDIUMCVSS 6.5fixed in 3.8.22026-09-04
CVE-2026-85583 [MEDIUM] CWE-59 CVE-2026-85583: SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-r SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace b
nvd
CVE-2026-82653P3HIGHCVSS 8.9fixed in 3.8.12026-08-30
CVE-2026-82653 [HIGH] CWE-79 CVE-2026-82653: SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where u SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unloc
nvd
CVE-2026-66394P3HIGHCVSS 8.7fixed in 3.7.32026-07-27
CVE-2026-66394 [HIGH] CWE-79 CVE-2026-66394: SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanit SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executab
nvd
CVE-2026-75917P3HIGHCVSS 8.6fixed in 3.7.42026-08-19
CVE-2026-75917 [HIGH] CWE-79 CVE-2026-75917: SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields (bookmark, alias, memo, and an alternate name field) are concatenated into the aria-label HTML attribut
nvd
CVE-2026-66395P3CRITICALCVSS 9.6fixed in 3.7.22026-07-27
CVE-2026-66395 [CRITICAL] CWE-79 CVE-2026-66395: SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar p SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML render
nvd
CVE-2026-85580P3MEDIUMCVSS 6.5fixed in 3.8.22026-09-04
CVE-2026-85580 [MEDIUM] CWE-22 CVE-2026-85580: SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handl SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
nvd
CVE-2026-87809P3MEDIUMCVSS 6.5fixed in 3.8.22026-09-09
CVE-2026-87809 [MEDIUM] CWE-639 CVE-2026-87809: Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of private, hidden, or publish-disabled blocks by accessing public documents containing embed queries that select those
nvd
CVE-2026-32938P3MEDIUMCVSS 6.5fixed in 3.6.12026-03-20
CVE-2026-32938 [MEDIUM] CWE-22 CVE-2026-32938: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2Bl SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list. Together with GET /assets/*path, which only requires authentication, a publi
nvd
CVE-2026-59853P3MEDIUMCVSS 6.5fixed in 3.7.12026-07-09
CVE-2026-59853 [MEDIUM] CWE-862 CVE-2026-59853: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getC SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths, notebook, document, and block IDs, an
nvd
CVE-2026-100633P3MEDIUMCVSS 6.5≥ 3.8.0, < 3.8.42026-09-26
CVE-2026-100633 [MEDIUM] CWE-863 CVE-2026-100633: SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the M SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path — an incomplete fix for GHSA-c8r8-95hg-mp34. An authenti
nvd
CVE-2026-74902P3HIGHCVSS 8.6fixed in 3.7.42026-08-18
CVE-2026-74902 [HIGH] CWE-79 CVE-2026-74902: SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flo SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the ed
nvd
CVE-2026-66396P3HIGHCVSS 8.4fixed in 3.7.22026-07-27
CVE-2026-66396 [HIGH] CWE-79 CVE-2026-66396: SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Ga SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access wh
nvd
CVE-2026-100645P3HIGHCVSS 8.0≥ 3.7.0, < 3.8.42026-09-26
CVE-2026-100645 [HIGH] CWE-79 CVE-2026-100645: SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery an SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands
nvd
CVE-2026-101091P3HIGHCVSS 7.1fixed in 3.8.42026-09-28
CVE-2026-101091 [HIGH] CWE-89 CVE-2026-101091: SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks e SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
nvd
CVE-2026-32750P3MEDIUMCVSS 6.8fixed in 3.6.12026-03-19
CVE-2026-32750 [MEDIUM] CWE-22 CVE-2026-32750: SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/impo SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads every file under the given path and permanently stores their content as SiYuan note documents in the workspace databa
nvd
CVE-2026-72812P3MEDIUMCVSS 6.5fixed in 3.7.42026-08-14
CVE-2026-72812 [MEDIUM] CWE-862 CVE-2026-72812: SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshB SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, byp
nvd
Siyuan-Note Siyuan vulnerabilities | cvebase