Where
-Infinity
0

SiYuan SiYuanSiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe srcdoc (incomplete fix for CVE-2026-33066)

Risk 34
Severity
5.3
First published (updated )

SiYuan SiYuanSiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE

Risk 75
Severity
9.1
First published (updated )

SiYuan SiYuanSiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

Risk 55
Severity
8.5
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API

Risk 60
Severity
8.1
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/siyuan-note/siyuan/kernelSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions

Risk 75
Severity
9.1
First published (updated )

SiYuan SiYuanSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )

Risk 73
Severity
8.6
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution

Risk 70
Severity
8.6
First published (updated )

SiYuan SiYuanSiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection

Risk 80
Severity
9.7
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client

Risk 75
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content

Risk 43
Severity
7.5
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has directory traversal within its publishing service

Risk 61
Severity
9.8
EPSS
0.06%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has Arbitrary Document Reading within the Publishing Service

Risk 61
Severity
9.8
EPSS
0.04%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has an Unauthenticated Arbitrary File Read via Path Traversal

Risk 31
Severity
7.5
EPSS
0.73%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass

Risk 31
Severity
7.5
EPSS
0.11%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/siyuan-note/siyuan/kernelSiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home

Risk 27
Severity
6.8
EPSS
0.04%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata

Risk 55
Severity
5.3
EPSS
0.07%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering

Risk 55
Severity
5.3
EPSS
0.21%
First published (updated )

go/github.com/siyuan-note/siyuanSiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)

Risk 48
Severity
9.3
EPSS
0.06%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan has an Arbitrary File Read in its Desktop Publish Service

Risk 56
Severity
9.9
EPSS
0.17%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/siyuan-note/siyuan/kernelSiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API

Risk 61
Severity
9.8
EPSS
0.02%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface

Risk 55
Severity
5.1
EPSS
0.36%
First published (updated )

go/github.com/siyuan-note/siyuanSiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes

Risk 27
Severity
6.8
EPSS
0.04%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write

Risk 54
Severity
9.1
EPSS
0.04%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure

Risk 31
Severity
5.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/siyuan-note/siyuan/kernelSiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets

Risk 27
Severity
6.8
EPSS
0.04%
First published (updated )

go/github.com/siyuan-note/siyuan/kernelSiYuan renderSprig: missing admin check allows any user to read full workspace DB

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

SiYuan SiYuanSiYuan has a Full-Read SSRF via /api/network/forwardProxy

Risk 49
Severity
8.3
EPSS
0.04%
First published (updated )

SiYuan SiYuanSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS

Risk 41
Severity
6.4
EPSS
0.03%
First published (updated )

SiYuan SiYuanSiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS

Risk 41
Severity
6.4
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203