Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

siyuan — Vulnerabilities & Security Advisories 77

All 77 CVE vulnerabilities found in siyuan, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Vulnerabilities and Exposures (CVEs) associated with SiYuan, an open-source personal knowledge management system. It aggregates reported security weaknesses affecting the SiYuan application and its underlying components, providing a centralized record for researchers and administrators monitoring the product's security posture. The content includes a comprehensive collection of identified vulnerabilities spanning from the project's inception through recent updates, ensuring a historical view of security issues as they have been disclosed and patched over time. Users can utilize this resource to track vendor advisories and understand the evolution of reported flaws within the SiYuan ecosystem. It serves as a reference point for comprehending specific weakness classes relevant to the software, such as input validation errors or privilege escalation bugs. Additionally, individuals can look up SiYuan's complete vulnerability history to assess the impact of past incidents on deployment stability or to perform risk assessments before upgrading. This structured overview aids in maintaining awareness of the current threat landscape specific to this productivity tool, allowing stakeholders to make informed decisions regarding updates and mitigation strategies without relying on scattered information sources.

Vendor: SiYuan

CVE IDTitleCVSSSeverityPublished
CVE-2026-40107 SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering CWE-918 6.1AIMediumAI2026-04-09
CVE-2026-39846 SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions CWE-79 9.1 Critical2026-04-07
CVE-2026-34605 SiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated ) CWE-79 6.1 -2026-03-31
CVE-2026-34585 SiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution CWE-79 8.6 High2026-03-31
CVE-2026-34449 SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection CWE-942 9.7 Critical2026-03-31
CVE-2026-34448 SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client CWE-79 9.1 Critical2026-03-31
CVE-2026-34453 SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content CWE-863 7.5 High2026-03-31
CVE-2026-33670 SiYuan has directory traversal within its publishing service CWE-22 9.8 Critical2026-03-26
CVE-2026-33669 SiYuan has Arbitrary Document Reading within the Publishing Service CWE-125 9.8 Critical2026-03-26
CVE-2026-33476 SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal CWE-22 7.5 High2026-03-20
CVE-2026-33203 SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass CWE-248 7.5 High2026-03-20
CVE-2026-33194 SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home CWE-22 6.8 Medium2026-03-20
CVE-2026-33067 SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata CWE-79 7.6 -2026-03-20
CVE-2026-33066 SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering CWE-79 5.4 -2026-03-20
CVE-2026-32940 SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183) CWE-79 9.3 Critical2026-03-20
CVE-2026-32938 SiYuan has an Arbitrary File Read in its Desktop Publish Service CWE-22 9.9 Critical2026-03-20
CVE-2026-32767 SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API CWE-89 9.8 Critical2026-03-20
CVE-2026-32815 SiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure CWE-287 9.1 -2026-03-19
CVE-2026-32750 SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes CWE-22 6.8 Medium2026-03-19
CVE-2026-32751 SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface CWE-79 5.4 -2026-03-19
CVE-2026-32749 SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write CWE-73 7.6 High2026-03-19
CVE-2026-32747 SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets CWE-22 6.8 Medium2026-03-19
CVE-2026-32704 SiYuan renderSprig: missing admin check allows any user to read full workspace DB CWE-285 6.5 Medium2026-03-13
CVE-2026-32110 SiYuan has a Full-Read SSRF via /api/network/forwardProxy CWE-918 8.3 High2026-03-11
CVE-2026-31809 SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS CWE-79 5.4AIMediumAI2026-03-10
CVE-2026-31807 SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS CWE-79 6.1AIMediumAI2026-03-10
CVE-2026-30869 SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage CWE-22 9.3 Critical2026-03-09
CVE-2026-30926 SiYuan Note publish service authorization bypass allows low-privilege users to modify notebook content CWE-284 7.1 High2026-03-09
CVE-2026-29183 SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution CWE-79 9.3 Critical2026-03-06
CVE-2026-29073 SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access CWE-862 8.8 -2026-03-06

All 77 known CVE vulnerabilities affecting siyuan with full Chinese analysis, references, and POCs where available.