Skip to content
Threat Feed

Vendor

B3log

3 briefs RSS
critical threat

SQL Injection in SiYuan via /api/search/searchEmbedBlock

SiYuan versions 3.7.2 and earlier contain a critical SQL injection vulnerability in the /api/search/searchEmbedBlock endpoint, allowing unauthenticated or low-privileged users to execute stacked SQL queries and modify database content.

exploited PoC SiYuan +1 sqli vulnerability web-application
1r 2t 2c 1i updated
high advisory

SiYuan Stored XSS via Malicious Bazaar Package README

A stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-54070, affects SiYuan versions up to 3.6.5, allowing a malicious third-party package author to embed JavaScript in package READMEs via an incomplete HTML sanitizer's blocklist, which executes in an Administrator's authenticated browser session upon viewing and interacting with the crafted README in the Bazaar marketplace, leading to API token theft and potential full workspace control.

siyuan-note/siyuan +2 xss web-vulnerability code-execution credential-theft si-yuan
5t 1c
critical threat

Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)

A critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.

Siyuan +6 langflow rce cve-2026-33017 ai-pipeline
2r 2t 1i updated