← Browse

Siyuan Note

86 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-59809 MEDIUM 6.9 Siyuan — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request M… 2026-08-22 CVE-2026-60083 MEDIUM 6.9 Siyuan — SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict… 2026-08-22 CVE-2026-60084 HIGH 8.4 Siyuan — SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTempla… 2026-08-22 CVE-2026-62204 MEDIUM 5.9 Siyuan — SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in baza… 2026-08-22 CVE-2026-77086 CRITICAL 9.4 Siyuan — SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, al… 2026-08-21 CVE-2026-75916 CRITICAL 9.3 Siyuan — SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hi…● PoC 2026-08-19 CVE-2026-75917 CRITICAL 9.3 Siyuan — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip gen…● PoC 2026-08-19 CVE-2026-74902 CRITICAL 9.3 Siyuan — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fai… 2026-08-18 CVE-2026-74903 MEDIUM 5.3 Siyuan — SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpo…● PoC 2026-08-18 CVE-2026-74904 HIGH 8.7 Siyuan — SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/bloc…● PoC 2026-08-18 CVE-2026-74905 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function i…● PoC 2026-08-18 CVE-2026-74906 HIGH 8.7 Siyuan — SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing end…● PoC 2026-08-18 CVE-2026-74798 CRITICAL 9.3 Siyuan — SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool p…● PoC 2026-08-17 CVE-2026-74799 CRITICAL 9.2 Siyuan — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without aut…● PoC 2026-08-17 CVE-2026-74800 CRITICAL 9.4 Siyuan — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrar… 2026-08-17 CVE-2026-74801 HIGH 8.6 Siyuan — SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line argument…● PoC 2026-08-17 CVE-2026-74802 N/A 0 Siyuan — SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/netw…● PoC 2026-08-17 CVE-2026-74867 LOW 2.3 Siyuan — SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authenti… 2026-08-17 CVE-2026-74868 HIGH 8.7 Siyuan — SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Aut…● PoC 2026-08-17 CVE-2026-73056 CRITICAL 9.3 Siyuan — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulne…● PoC 2026-08-16 CVE-2026-73041 CRITICAL 9.4 Siyuan — SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnot…● PoC 2026-08-15 CVE-2026-73042 CRITICAL 9.4 Siyuan — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored va… 2026-08-15 CVE-2026-73043 CRITICAL 9.4 Siyuan — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operat… 2026-08-15 CVE-2026-73044 CRITICAL 9.4 Siyuan — SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site…● PoC 2026-08-15 CVE-2026-73045 HIGH 8.7 Siyuan — SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the…● PoC 2026-08-15 CVE-2026-73046 CRITICAL 9.3 Siyuan — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The…● PoC 2026-08-15 CVE-2026-73047 HIGH 8.6 Siyuan — siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attri… 2026-08-15 CVE-2026-73050 CRITICAL 9.4 Siyuan — SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, all…● PoC 2026-08-15 CVE-2026-73052 CRITICAL 9.4 Siyuan — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly in…● PoC 2026-08-15 CVE-2026-73053 CRITICAL 9.4 Siyuan — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that …● PoC 2026-08-15 CVE-2026-73054 HIGH 8.7 Siyuan — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused …● PoC 2026-08-15 CVE-2026-72810 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions …● PoC 2026-08-14 CVE-2026-72811 CRITICAL 9.9 Siyuan — SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/m… 2026-08-14 CVE-2026-72812 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink en… 2026-08-14 CVE-2026-73048 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotation…● PoC 2026-08-14 CVE-2026-73049 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks…● PoC 2026-08-14 CVE-2026-73630 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAcce… 2026-08-14 CVE-2026-73605 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that al… 2026-08-13 CVE-2026-73606 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endp…● PoC 2026-08-13 CVE-2026-73607 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineSt…● PoC 2026-08-13 CVE-2026-73608 CRITICAL 9.2 Siyuan — SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched…● PoC 2026-08-13 CVE-2026-73609 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoin… 2026-08-13 CVE-2026-73610 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns…● PoC 2026-08-13 CVE-2026-72788 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fail…● PoC 2026-08-12 CVE-2026-72789 CRITICAL 9.2 Siyuan — SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publi…● PoC 2026-08-12 CVE-2026-72790 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo end…● PoC 2026-08-12 CVE-2026-72791 MEDIUM 6.9 Siyuan — SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an inf… 2026-08-12 CVE-2026-72792 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that ret… 2026-08-12 CVE-2026-72793 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint,…● PoC 2026-08-12 CVE-2026-72794 CRITICAL 9.2 Siyuan — siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint t…● PoC 2026-08-12 CVE-2026-72795 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEm…● PoC 2026-08-12 CVE-2026-72796 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mu… 2026-08-12 CVE-2026-72797 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatu…● PoC 2026-08-12 CVE-2026-72798 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowin… 2026-08-12 CVE-2026-72799 MEDIUM 6.9 Siyuan — SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolut… 2026-08-12 CVE-2026-72800 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint,… 2026-08-12 CVE-2026-72801 HIGH 8.7 Siyuan — SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys throug…● PoC 2026-08-12 CVE-2026-72802 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint…● PoC 2026-08-12 CVE-2026-72803 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttr…● PoC 2026-08-12 CVE-2026-72804 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, … 2026-08-12 CVE-2026-72805 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and get…● PoC 2026-08-12 CVE-2026-72806 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess …● PoC 2026-08-12 CVE-2026-72807 HIGH 8.8 Siyuan — SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template co… 2026-08-12 CVE-2026-72808 MEDIUM 6.9 Siyuan — SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability i…● PoC 2026-08-12 CVE-2026-72809 HIGH 7.1 Siyuan — SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's C…● PoC 2026-08-12 CVE-2026-68584 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-ret… 2026-08-03 CVE-2026-68585 MEDIUM 6.9 Siyuan — SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpo…● PoC 2026-08-03 CVE-2026-68586 CRITICAL 9.2 Siyuan — SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content… 2026-08-03 CVE-2026-68587 CRITICAL 9.2 Siyuan — SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransacti…● PoC 2026-08-03 CVE-2026-69083 CRITICAL 9.9 Siyuan — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint…● PoC 2026-08-03 CVE-2026-69084 CRITICAL 9.9 Siyuan — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL…● PoC 2026-08-03 CVE-2026-69085 CRITICAL 9.9 Siyuan — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where th…● PoC 2026-08-03 CVE-2026-69086 HIGH 8.3 Siyuan — SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read … 2026-08-03 CVE-2026-66394 CRITICAL 9.3 Siyuan — SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization th…● PoC 2026-07-27 CVE-2026-66395 CRITICAL 9.4 Siyuan — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin read…● PoC 2026-07-27 CVE-2026-66396 CRITICAL 9.3 Siyuan — SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and …● PoC 2026-07-27 CVE-2026-66012 CRITICAL 10 Siyuan — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is…● PoC 2026-07-25 CVE-2026-65605 CRITICAL 9.4 Siyuan — SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell re…● PoC 2026-07-23 CVE-2026-65606 CRITICAL 9.4 Siyuan — SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a s…● PoC 2026-07-23 CVE-2026-65607 HIGH 7.1 Siyuan — SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the … 2026-07-23 CVE-2026-59832 HIGH 7.7 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route h… 2026-07-09 CVE-2026-59833 HIGH 8.6 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package…● PoC 2026-07-09 CVE-2026-59834 HIGH 7.5 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST …● PoC 2026-07-09 CVE-2026-59853 MEDIUM 6.5 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria en…● PoC 2026-07-09 CVE-2026-59854 MEDIUM 4.9 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles … 2026-07-09 CVE-2026-59855 HIGH 8.6 Siyuan — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/i…● PoC 2026-07-09