VulnSea

github.com/siyuan-note/siyuan/kernel vulnerabilities

CVEs whose affected-version data names the github.com/siyuan-note/siyuan/kernel package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

53 CVEsRSS

CVE-2026-66394High· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.27%via OSV
GHSA-99rq-75j6-5j9fHigh· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-gw25-m53r-qh88Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-59834High· 7.5
3w ago

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-59832High· 7.7
3w ago

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.46%via OSV
GHSA-xx34-6cjg-prh8Critical· 8.6
1mo ago

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-mxjf-vfmv-qfm6Medium· 5.8
1mo ago

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-72809High· 8.0
1mo ago

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.21%via NVD
CVE-2026-72805Medium· 5.8
1mo ago

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via NVD
CVE-2026-72789High· 8.6
1mo ago

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.29%via NVD
GHSA-g64v-qqpg-v37hCritical· 8.6
1mo ago

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-50551Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.78%via GHSA
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-54068Medium· 5.9
2mo ago

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via GHSA
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVE-2026-54070High· 7.1
2mo ago

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-56395Medium
3mo ago

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via NVD
CVE-2026-40922Medium· 5.4
5mo ago

SiYuan has incomplete fix for CVE-2026-33066: XSS

SiYuan has incomplete fix for CVE-2026-33066: XSS

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via OSV
CVE-2026-33066Medium
6mo ago

SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering

SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via OSV
CVE-2026-56397Medium
6mo ago

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via GHSA
github.com/siyuan-note/siyuan/kernel vulnerabilities (CVEs) — page 2 · VulnSea