Siyuan Note
86 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-59809
MEDIUM 6.9
Siyuan — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request M…
2026-08-22
CVE-2026-60083
MEDIUM 6.9
Siyuan — SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict…
2026-08-22
CVE-2026-60084
HIGH 8.4
Siyuan — SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTempla…
2026-08-22
CVE-2026-62204
MEDIUM 5.9
Siyuan — SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in baza…
2026-08-22
CVE-2026-77086
CRITICAL 9.4
Siyuan — SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, al…
2026-08-21
CVE-2026-75916
CRITICAL 9.3
Siyuan — SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hi…● PoC
2026-08-19
CVE-2026-75917
CRITICAL 9.3
Siyuan — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip gen…● PoC
2026-08-19
CVE-2026-74902
CRITICAL 9.3
Siyuan — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fai…
2026-08-18
CVE-2026-74903
MEDIUM 5.3
Siyuan — SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpo…● PoC
2026-08-18
CVE-2026-74904
HIGH 8.7
Siyuan — SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/bloc…● PoC
2026-08-18
CVE-2026-74905
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function i…● PoC
2026-08-18
CVE-2026-74906
HIGH 8.7
Siyuan — SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing end…● PoC
2026-08-18
CVE-2026-74798
CRITICAL 9.3
Siyuan — SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool p…● PoC
2026-08-17
CVE-2026-74799
CRITICAL 9.2
Siyuan — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without aut…● PoC
2026-08-17
CVE-2026-74800
CRITICAL 9.4
Siyuan — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrar…
2026-08-17
CVE-2026-74801
HIGH 8.6
Siyuan — SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line argument…● PoC
2026-08-17
CVE-2026-74802
N/A 0
Siyuan — SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/netw…● PoC
2026-08-17
CVE-2026-74867
LOW 2.3
Siyuan — SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authenti…
2026-08-17
CVE-2026-74868
HIGH 8.7
Siyuan — SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Aut…● PoC
2026-08-17
CVE-2026-73056
CRITICAL 9.3
Siyuan — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulne…● PoC
2026-08-16
CVE-2026-73041
CRITICAL 9.4
Siyuan — SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnot…● PoC
2026-08-15
CVE-2026-73042
CRITICAL 9.4
Siyuan — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored va…
2026-08-15
CVE-2026-73043
CRITICAL 9.4
Siyuan — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operat…
2026-08-15
CVE-2026-73044
CRITICAL 9.4
Siyuan — SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site…● PoC
2026-08-15
CVE-2026-73045
HIGH 8.7
Siyuan — SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the…● PoC
2026-08-15
CVE-2026-73046
CRITICAL 9.3
Siyuan — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The…● PoC
2026-08-15
CVE-2026-73047
HIGH 8.6
Siyuan — siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attri…
2026-08-15
CVE-2026-73050
CRITICAL 9.4
Siyuan — SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, all…● PoC
2026-08-15
CVE-2026-73052
CRITICAL 9.4
Siyuan — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly in…● PoC
2026-08-15
CVE-2026-73053
CRITICAL 9.4
Siyuan — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that …● PoC
2026-08-15
CVE-2026-73054
HIGH 8.7
Siyuan — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused …● PoC
2026-08-15
CVE-2026-72810
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions …● PoC
2026-08-14
CVE-2026-72811
CRITICAL 9.9
Siyuan — SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/m…
2026-08-14
CVE-2026-72812
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink en…
2026-08-14
CVE-2026-73048
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotation…● PoC
2026-08-14
CVE-2026-73049
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks…● PoC
2026-08-14
CVE-2026-73630
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAcce…
2026-08-14
CVE-2026-73605
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that al…
2026-08-13
CVE-2026-73606
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endp…● PoC
2026-08-13
CVE-2026-73607
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineSt…● PoC
2026-08-13
CVE-2026-73608
CRITICAL 9.2
Siyuan — SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched…● PoC
2026-08-13
CVE-2026-73609
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoin…
2026-08-13
CVE-2026-73610
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns…● PoC
2026-08-13
CVE-2026-72788
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fail…● PoC
2026-08-12
CVE-2026-72789
CRITICAL 9.2
Siyuan — SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publi…● PoC
2026-08-12
CVE-2026-72790
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo end…● PoC
2026-08-12
CVE-2026-72791
MEDIUM 6.9
Siyuan — SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an inf…
2026-08-12
CVE-2026-72792
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that ret…
2026-08-12
CVE-2026-72793
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint,…● PoC
2026-08-12
CVE-2026-72794
CRITICAL 9.2
Siyuan — siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint t…● PoC
2026-08-12
CVE-2026-72795
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEm…● PoC
2026-08-12
CVE-2026-72796
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mu…
2026-08-12
CVE-2026-72797
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatu…● PoC
2026-08-12
CVE-2026-72798
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowin…
2026-08-12
CVE-2026-72799
MEDIUM 6.9
Siyuan — SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolut…
2026-08-12
CVE-2026-72800
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint,…
2026-08-12
CVE-2026-72801
HIGH 8.7
Siyuan — SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys throug…● PoC
2026-08-12
CVE-2026-72802
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint…● PoC
2026-08-12
CVE-2026-72803
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttr…● PoC
2026-08-12
CVE-2026-72804
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, …
2026-08-12
CVE-2026-72805
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and get…● PoC
2026-08-12
CVE-2026-72806
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess …● PoC
2026-08-12
CVE-2026-72807
HIGH 8.8
Siyuan — SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template co…
2026-08-12
CVE-2026-72808
MEDIUM 6.9
Siyuan — SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability i…● PoC
2026-08-12
CVE-2026-72809
HIGH 7.1
Siyuan — SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's C…● PoC
2026-08-12
CVE-2026-68584
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-ret…
2026-08-03
CVE-2026-68585
MEDIUM 6.9
Siyuan — SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpo…● PoC
2026-08-03
CVE-2026-68586
CRITICAL 9.2
Siyuan — SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content…
2026-08-03
CVE-2026-68587
CRITICAL 9.2
Siyuan — SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransacti…● PoC
2026-08-03
CVE-2026-69083
CRITICAL 9.9
Siyuan — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint…● PoC
2026-08-03
CVE-2026-69084
CRITICAL 9.9
Siyuan — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL…● PoC
2026-08-03
CVE-2026-69085
CRITICAL 9.9
Siyuan — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where th…● PoC
2026-08-03
CVE-2026-69086
HIGH 8.3
Siyuan — SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read …
2026-08-03
CVE-2026-66394
CRITICAL 9.3
Siyuan — SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization th…● PoC
2026-07-27
CVE-2026-66395
CRITICAL 9.4
Siyuan — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin read…● PoC
2026-07-27
CVE-2026-66396
CRITICAL 9.3
Siyuan — SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and …● PoC
2026-07-27
CVE-2026-66012
CRITICAL 10
Siyuan — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is…● PoC
2026-07-25
CVE-2026-65605
CRITICAL 9.4
Siyuan — SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell re…● PoC
2026-07-23
CVE-2026-65606
CRITICAL 9.4
Siyuan — SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a s…● PoC
2026-07-23
CVE-2026-65607
HIGH 7.1
Siyuan — SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the …
2026-07-23
CVE-2026-59832
HIGH 7.7
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route h…
2026-07-09
CVE-2026-59833
HIGH 8.6
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package…● PoC
2026-07-09
CVE-2026-59834
HIGH 7.5
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST …● PoC
2026-07-09
CVE-2026-59853
MEDIUM 6.5
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria en…● PoC
2026-07-09
CVE-2026-59854
MEDIUM 4.9
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles …
2026-07-09
CVE-2026-59855
HIGH 8.6
Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/i…● PoC
2026-07-09