VulnSea

github.com/siyuan-note/siyuan/kernel vulnerabilities

CVEs whose affected-version data names the github.com/siyuan-note/siyuan/kernel package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

53 CVEsRSS

CVE-2026-93922High· 8.8
3d ago

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that exec…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via NVD
CVE-2026-93923High· 8.8PoC
3d ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via NVD
CVE-2026-93921Medium· 4.3PoC
3d ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.23%via NVD
GHSA-57v5-wqx3-cgj4Medium· 5.8
2w ago

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia OSV
CVE-2026-72790Medium· 5.8
2w ago

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-72799Medium· 5.8
2w ago

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-72798High· 8.6
2w ago

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via GHSA
CVE-2026-72796Medium· 5.8
2w ago

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via GHSA
CVE-2026-72794High· 8.6
2w ago

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.25%via OSV
CVE-2026-72795High· 8.6
2w ago

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via GHSA
CVE-2026-72792Medium· 5.8
2w ago

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via GHSA
CVE-2026-68584High· 8.6
2w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.31%via OSV
CVE-2026-72812Medium· 6.5
2w ago

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.27%via GHSA
CVE-2026-72811Critical· 10.0
2w ago

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.25%via GHSA
CVE-2026-72810High· 8.6
2w ago

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.31%via GHSA
CVE-2026-72808Medium· 5.8
2w ago

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.28%via GHSA
CVE-2026-72807High· 8.0
2w ago

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.20%via GHSA
CVE-2026-72806Medium· 5.8
2w ago

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.31%via OSV
CVE-2026-72804High· 8.6
2w ago

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via GHSA
CVE-2026-72803Medium· 5.8
2w ago

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via GHSA
CVE-2026-72802Medium· 5.3
2w ago

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via GHSA
CVE-2026-72800Medium· 5.8
2w ago

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeratio…

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-68587High· 8.6
2w ago

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rende…

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-68586High· 8.6
2w ago

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-f…

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-68585Medium· 5.8
2w ago

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.19%via GHSA
GHSA-7j72-f6wg-cxw6High· 8.6
2w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-69084Critical· 10.0PoC
2w ago

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 1.1%via GHSA
CVE-2026-69086High· 7.7
2w ago

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.35%via OSV
CVE-2026-69083Critical· 10.0PoC
2w ago

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.35%via GHSA
CVE-2026-65607Medium· 6.5
2w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.59%via OSV
github.com/siyuan-note/siyuan/kernel vulnerabilities (CVEs) · VulnSea