Skip to content
Threat Feed

Vendor

SiYuan

10 briefs RSS
high advisory

Authentication Bypass Vulnerability in SiYuan Publish Mode

SiYuan versions before 3.7.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve content from password-protected documents.

SiYuan
2t 1c
critical advisory

SiYuan Stored XSS Leads to Remote Code Execution (CVE-2026-66396)

SiYuan before v3.7.2 is vulnerable to stored cross-site scripting (XSS) due to improper escaping of the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing attackers with editor permissions to inject malicious onload handlers that execute arbitrary code in the Electron renderer with full Node.js access, leading to remote code execution.

SiYuan xss remote-code-execution client-side-exploitation electron
2t 1c
critical advisory

SiYuan Missing Authorization Vulnerability in /mcp Endpoint (CVE-2026-66012)

A critical missing authorization vulnerability, CVE-2026-66012, in SiYuan before version 3.7.2 allows a remote unauthenticated attacker to exploit the POST /mcp kernel endpoint when the Publish server is in anonymous mode, leading to arbitrary file writes, sensitive credential exposure, malicious plugin execution, and ultimately administrator takeover on affected systems.

SiYuan < v3.7.2 vulnerability rce authorization-bypass siyuan cve-2026-66012
5t 2i updated
critical advisory

CVE-2026-65606 - SiYuan XSS to RCE Vulnerability

A critical cross-site scripting (XSS) vulnerability, CVE-2026-65606, exists in SiYuan desktop application versions prior to 3.7.2's `siyuan://` protocol handler, allowing an attacker to inject an unescaped `<img>` element into the tab header, leading to arbitrary JavaScript execution and ultimately operating system command execution due to `nodeIntegration:true`.

SiYuan xss rce desktop-application vulnerability cve
2t 1c
critical advisory

SiYuan Unauthenticated Admin API Access via Chrome Extension Allowlist

A critical vulnerability (CVE-2026-54069) in SiYuan Note kernel's HTTP server allows any Chrome/Chromium browser extension to gain unauthenticated RoleAdministrator access, enabling data exfiltration, stored XSS injection, and configuration tampering for SiYuan desktop users, including via compromised legitimate extensions.

SiYuan Note +1 web-vulnerability privilege-escalation data-exfiltration xss supply-chain desktop-application chrome-extension siyuan
1r 6t 1c 1i
high advisory

SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding

An incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.

siyuan kernel path-traversal vulnerability web-vulnerability arbitrary-file-read
1r 3t 2c 1i
high advisory

SiYuan Path Traversal via Double URL Encoding in `/export/` Endpoint

SiYuan is vulnerable to path traversal via double URL encoding in the `/export/` endpoint, bypassing an incomplete fix for CVE-2026-30869; an authenticated attacker can exploit this vulnerability to traverse directories and read arbitrary workspace files, including the SQLite database (`siyuan.db`), kernel log, and user documents due to a redundant `url.PathUnescape()` call in `serveExport()`.

siyuan path-traversal web-application
2r 1t 1c 1i
critical advisory

SiYuan Knowledge Management System RCE via Mermaid Diagram Injection

SiYuan versions 3.6.3 and below are vulnerable to arbitrary code execution due to insecure rendering of Mermaid diagrams, allowing injected javascript: URLs within Mermaid code blocks to execute arbitrary code when a victim opens a note containing a malicious Mermaid block and clicks the rendered diagram node.

SiYuan Knowledge Management System siyuan mermaid rce xss electron
2r 1t 1c
critical advisory

SiYuan Path Traversal Vulnerability (CVE-2026-40318)

SiYuan versions 3.6.3 and prior are vulnerable to path traversal (CVE-2026-40318), allowing attackers to delete arbitrary .json files on the server via the /api/av/removeUnusedAttributeView endpoint.

SiYuan path-traversal vulnerability
3r 1t 1c
high advisory

SiYuan Unauthorized Attribute View Deletion Vulnerability (CVE-2026-40259)

SiYuan versions 3.6.3 and below are vulnerable to unauthorized attribute view deletion via the /api/av/removeUnusedAttributeView endpoint, allowing authenticated users with publish-service RoleReader tokens to delete arbitrary attribute view definitions, leading to database view breakage and workspace rendering issues.

SiYuan attribute-deletion vulnerability webserver
2r 1c