github.com/siyuan-note/siyuan/kernel vulnerabilities
CVEs whose affected-version data names the github.com/siyuan-note/siyuan/kernel package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
53 CVEsRSS
CVE-2026-66394High· 8.7SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
GHSA-99rq-75j6-5j9fHigh· 8.7SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
GHSA-gw25-m53r-qh88Medium· 6.5SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
CVE-2026-59834High· 7.5SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
CVE-2026-59832High· 7.7Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
GHSA-xx34-6cjg-prh8Critical· 8.6Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
GHSA-mxjf-vfmv-qfm6Medium· 5.8Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
CVE-2026-72809High· 8.0SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…
CVE-2026-72805Medium· 5.8SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata
SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…
CVE-2026-72789High· 8.6SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…
GHSA-g64v-qqpg-v37hCritical· 8.6Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
CVE-2026-50551Critical· 9.9SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
CVE-2026-54067Critical· 9.9SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-54068Medium· 5.9SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
CVE-2026-54069CriticalPoCSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
CVE-2026-54070High· 7.1SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
CVE-2026-54158Critical· 9.9SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
GHSA-24r3-p3x6-cqvxCritical· 9.6Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-56395MediumRejected reason: This record is a duplicate; use CVE-2026-56397 instead.
Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.
CVE-2026-40922Medium· 5.4SiYuan has incomplete fix for CVE-2026-33066: XSS
SiYuan has incomplete fix for CVE-2026-33066: XSS
CVE-2026-33066MediumSiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS