siyuan-note siyuan
57 known vulnerabilities in siyuan-note siyuan, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105205 CVSS 6.9 medium SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and…
- CVE-2026-104410 CVSS 8.7 high SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and…
- CVE-2026-103763 CVSS 6.9 medium SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of…
- CVE-2026-103762 CVSS 6.9 medium SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and…
- CVE-2026-101092 CVSS 6.9 medium SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve…
- CVE-2026-101091 CVSS 7.1 high SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers…
- CVE-2026-100646 CVSS 8.6 high SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards…
- CVE-2026-100645 CVSS 8.6 high SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where…
- CVE-2026-100644 CVSS 8.7 high SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is…
- CVE-2026-100643 CVSS 8.5 high SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated…
- CVE-2026-100642 CVSS 7.2 high SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through…
- CVE-2026-100641 CVSS 8.6 high SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block…
- CVE-2026-100640 CVSS 8.6 high SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native…
- CVE-2026-100639 CVSS 8.6 high SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts…
- CVE-2026-100638 CVSS 8.3 high SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated…
- CVE-2026-100637 CVSS 8.3 high SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators…
- CVE-2026-100636 CVSS 8.3 high SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated…
- CVE-2026-100635 CVSS 8.2 high SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without…
- CVE-2026-100634 CVSS 5.3 medium SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main…
- CVE-2026-100633 CVSS 8.5 high SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard…
- CVE-2026-93923 CVSS 8.6 high SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site…
- CVE-2026-93922 CVSS 8.6 high SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site…
- CVE-2026-93921 CVSS 5.3 medium SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to…
- CVE-2026-93591 CVSS 7.2 high SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated…
- CVE-2026-92986 CVSS 8.6 high SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set…
- CVE-2026-92985 CVSS 8.6 high SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers…
- CVE-2026-87815 CVSS 8.4 high SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the…
- CVE-2026-87814 CVSS 8.4 high SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed…
- CVE-2026-87813 CVSS 8.4 high SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are…
- CVE-2026-87812 CVSS 7.4 high SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted…