Siyuan-Note Siyuan vulnerabilities
201 known vulnerabilities affecting siyuan-note/siyuan.
Total CVEs
201
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH90MEDIUM70
Vulnerabilities
Page 8 of 11
CVE-2026-86192P3MEDIUMCVSS 6.5fixed in 3.8.22026-09-05
CVE-2026-86192 [MEDIUM] CWE-639 CVE-2026-86192: SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getA
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
nvd
CVE-2026-87814P3HIGHCVSS 7.3fixed in 3.8.22026-09-09
CVE-2026-87814 [HIGH] CWE-79 CVE-2026-87814: SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset previe
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authen
nvd
CVE-2026-87813P3HIGHCVSS 7.3fixed in 3.8.22026-09-09
CVE-2026-87813 [HIGH] CWE-79 CVE-2026-87813: SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets resul
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing malicious markup that executes JavaScript in the victim's browser when searching assets, enabling same-origin API reque
nvd
CVE-2026-72806P3MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72806 [MEDIUM] CWE-862 CVE-2026-72806: SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPubl
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttr
nvd
CVE-2026-82233P3MEDIUMCVSS 5.7fixed in 3.8.12026-08-28
CVE-2026-82233 [MEDIUM] CWE-22 CVE-2026-82233: SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accep
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside the workspace into the asset directory through prompt injection.
nvd
CVE-2026-100642P3HIGHCVSS 7.6≥ 2.1.0, < 3.8.42026-09-26
CVE-2026-100642 [HIGH] CWE-346 CVE-2026-100642: SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration
nvd
CVE-2026-54070P3HIGHCVSS 7.1fixed in 3.7.02026-06-24
CVE-2026-54070 [HIGH] CWE-79 CVE-2026-54070: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME i
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute sanitizer is an event-handler blocklist: allowAttr rejects only attribute names present in a fixed eventAttrs map copied
nvd
CVE-2026-54068P3MEDIUMCVSS 5.9fixed in 3.7.02026-06-24
CVE-2026-54068 [MEDIUM] CWE-306 CVE-2026-54068: SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDyna
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). When called with type=8 and a valid block id parameter, this endpoint invokes RenderDynamicIconContentTemplate, which execute
nvd
CVE-2026-33194P3MEDIUMCVSS 6.8fixed in 3.6.22026-03-20
CVE-2026-33194 [MEDIUM] CWE-22 CVE-2026-33194: SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` fu
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/util/path.go` uses a denylist approach that was recently expanded (GHSA-h5vh-m7fg-w5h6, commit 9914fd1) but remains incomplete. Multiple security-relevant Linux directories are not blocked, including `/opt` (application data), `/usr`
nvd
CVE-2026-40107P3MEDIUMCVSS 6.5fixed in 3.6.42026-04-09
CVE-2026-40107 [MEDIUM] CWE-918 CVE-2026-40107: SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with
SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, tags with src attributes survive Mermaid's internal DOMPurify and land in SVG blocks. The SVG is injected via innerHTML with no secondary sanitization. When a victim opens a note containing a m
nvd
CVE-2026-100635P3MEDIUMCVSS 5.9fixed in 3.8.42026-09-26
CVE-2026-100635 [MEDIUM] CWE-319 CVE-2026-100635: SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where se
SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoi
nvd
CVE-2026-73605P3MEDIUMCVSS 5.8fixed in 3.7.42026-08-13
CVE-2026-73605 [MEDIUM] CWE-862 CVE-2026-73605: SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoi
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem lay
nvd
CVE-2026-85582P3MEDIUMCVSS 6.5fixed in 3.8.22026-09-04
CVE-2026-85582 [MEDIUM] CWE-770 CVE-2026-85582: SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-ser
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growt
nvd
CVE-2026-72796P3MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72796 [MEDIUM] CWE-862 CVE-2026-72796: SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the
SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts by directly accessing static routes that lack the sa
nvd
CVE-2026-72800P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72800 [MEDIUM] CWE-862 CVE-2026-72800: SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID
SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-w
nvd
CVE-2026-72788P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72788 [MEDIUM] CWE-863 CVE-2026-72788: SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint w
nvd
CVE-2026-72808P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72808 [MEDIUM] CWE-862 CVE-2026-72808: SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulne
SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by CheckAuth (unlike the /assets/* route, which enforces publish access and passwo
nvd
CVE-2026-73630P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-14
CVE-2026-73630 [MEDIUM] CWE-203 CVE-2026-73630: SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFileP
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never sets a failure code, so its outcome is signalled entirely by the response message and by the presence of a Set-Cookie header, and these sig
nvd
CVE-2026-72791P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-12
CVE-2026-72791 [MEDIUM] CWE-862 CVE-2026-72791: SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) conta
SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeViewFieldViews endpoint. The route is registered with CheckAuth only and applies no publish-access filtering, so reader-role callers can retrieve the complete database view structu
nvd
CVE-2026-73048P4MEDIUMCVSS 5.8fixed in 3.7.42026-08-14
CVE-2026-73048 [MEDIUM] CWE-862 CVE-2026-73048: SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFile
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing c
nvd