Siyuan Note: Batch of 13 Vulnerabilities Includes Critical XSS and DoS Flaws
Siyuan Note: 13 vulnerabilities disclosed, including critical XSS and high-severity flaws, fixed in v3.8.2.

Key findings
- Critical stored XSS (CVE-2026-84803) due to incomplete extension blocklist in asset serving.
- High-severity path traversal (CVE-2026-85175) allows access to sensitive TLS/CA keys.
- High-severity plaintext API token logging (CVE-2026-85174) enables persistent admin access.
- Multiple denial-of-service vulnerabilities (CVE-2026-85583, CVE-2026-85581, CVE-2026-85584) can exhaust system resources.
- All 13 vulnerabilities are fixed in Siyuan Note v3.8.2.
On September 2nd, 2026, a batch of 13 vulnerabilities affecting Siyuan Note versions prior to v3.8.2 was disclosed. These vulnerabilities, disclosed over a three-day period, range in severity from Medium to Critical, with several high-severity flaws impacting authentication, resource consumption, and sensitive data access. The disclosures highlight significant security weaknesses in the note-taking application's handling of user input, authentication mechanisms, and file access controls.
Several vulnerabilities center on information disclosure and unauthorized access. CVE-2026-86192 and CVE-2026-86191, both Medium severity, allow unauthorized retrieval of hidden KeyValues payloads and enumeration of private attribute view key definitions, respectively, by publish readers. CVE-2026-85580, also Medium severity, details a path guard bypass allowing attackers to read sensitive publish-access configurations by exploiting case-sensitive matching on Linux filesystems. Furthermore, CVE-2026-85578 (Medium severity) permits readers to access private notebook files and configurations by bypassing visibility settings. CVE-2026-85579 (Medium severity) involves an information disclosure vulnerability in the undoState endpoint, returning sensitive data without proper access control.
A significant cluster of vulnerabilities relates to denial of service (DoS) and resource exhaustion. CVE-2026-85583 (High severity) describes an unbounded resource consumption vulnerability in the request-concurrency middleware, allowing unauthenticated attackers to exhaust process memory by sending numerous unique request paths. Similarly, CVE-2026-85581 (High severity) details a DoS vulnerability in the unauthenticated /api/system/uiproc endpoint, where attackers can exhaust process memory by sending repeated requests with unique identifiers. CVE-2026-85582 (Medium severity) points to an unbounded session creation vulnerability in the publish-service Basic Auth handler, enabling authenticated attackers to exhaust memory by repeatedly authenticating. CVE-2026-85584 (High severity) is another DoS vulnerability in the publish-service Basic Auth throttle, allowing unauthenticated attackers to repeatedly submit authentication requests with unique usernames to exhaust resources.
The batch also includes critical and high-severity flaws related to sensitive data exposure and code execution. CVE-2026-84803, a Critical stored XSS vulnerability, arises from an incomplete extension blocklist in asset serving, allowing attackers to upload malicious files that execute JavaScript. CVE-2026-85175, a High severity path traversal vulnerability, allows readers to access sensitive TLS and CA private keys by following symlinks outside the workspace. CVE-2026-85174, also High severity, involves plaintext logging of API tokens in an accessible log file, enabling attackers to recover admin API tokens and gain persistent administrative access.
All 13 vulnerabilities were fixed in Siyuan Note v3.8.2. Users are strongly urged to update to this version immediately to mitigate the risks associated with these critical, high, and medium severity flaws. The timely disclosure and patching of these issues are crucial for maintaining the security and integrity of user data within the Siyuan Note application.
The disclosure of this batch of vulnerabilities, particularly the critical stored XSS and high-severity authentication bypasses, underscores the importance of robust input validation and access control mechanisms in applications handling sensitive user data. Users should prioritize updating to the patched version to protect against potential exploitation.
The batch of vulnerabilities was disclosed between September 2nd and September 5th, 2026, affecting Siyuan Note versions prior to v3.8.2. The most severe issues include a critical stored XSS flaw (CVE-2026-84803), high-severity path traversal allowing access to sensitive keys (CVE-2026-85175), and high-severity plaintext API token logging (CVE-2026-85174). Other vulnerabilities include multiple denial-of-service and information disclosure flaws. All issues have been addressed in Siyuan Note v3.8.2. Vypr Intelligence
A critical stored XSS vulnerability (CVE-2026-84803) allows arbitrary JavaScript execution. High-severity flaws include path traversal to sensitive keys (CVE-2026-85175) and plaintext API token logging (CVE-2026-85174). Multiple denial-of-service vulnerabilities (CVE-2026-85583, CVE-2026-85581, CVE-2026-85584) can exhaust system resources. Information disclosure vulnerabilities (CVE-2026-86192, CVE-2026-86191, CVE-2026-85580, CVE-2026-85578, CVE-2026-85579) expose private data and configurations. All 13 vulnerabilities are fixed in Siyuan Note v3.8.2. CVE-2026-84803, CVE-2026-85174, CVE-2026-85175 are among the disclosed vulnerabilities. CVE-2026-85578, CVE-2026-85579, CVE-2026-85580, CVE-2026-85581, CVE-2026-85582, CVE-2026-85583, CVE-2026-85584, CVE-2026-86191, CVE-2026-86192 are also part of this disclosure. CVE-2026-85174, CVE-2026-85175, CVE-2026-84803 were disclosed on September 2nd and 3rd, 2026.