Siyuan
by Siyuan Note
Source repositories
CVEs (212)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66012 | Cri | 0.65 | 10.0 | 0.01 | Jul 25, 2026 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with… | ||
| CVE-2026-73056 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2026 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter,… | ||
| CVE-2026-73046 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2026 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but… | ||
| CVE-2024-53507 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2024 | A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. | ||
| CVE-2024-53506 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. | ||
| CVE-2024-53505 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. | ||
| CVE-2024-53504 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. | ||
| CVE-2026-66395 | Cri | 0.62 | 9.6 | 0.01 | Jul 27, 2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter… | ||
| CVE-2026-65606 | Cri | 0.62 | 9.6 | 0.01 | Jul 23, 2026 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab… | ||
| CVE-2026-65605 | Cri | 0.62 | 9.6 | 0.01 | Jul 23, 2026 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true;… | ||
| CVE-2026-74799 | Cri | 0.60 | 9.3 | 0.01 | Aug 17, 2026 | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including… | ||
| CVE-2026-77086 | Cri | 0.59 | 9.1 | 0.01 | Aug 21, 2026 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location… | ||
| CVE-2026-74800 | Cri | 0.59 | 9.0 | 0.00 | Aug 17, 2026 | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when… | ||
| CVE-2026-73053 | Cri | 0.59 | 9.0 | 0.01 | Aug 15, 2026 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled,… | ||
| CVE-2026-73052 | Cri | 0.59 | 9.0 | 0.01 | Aug 15, 2026 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort… | ||
| CVE-2026-73050 | Cri | 0.59 | 9.0 | 0.00 | Aug 15, 2026 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value,… | ||
| CVE-2026-73044 | Cri | 0.59 | 9.0 | 0.00 | Aug 15, 2026 | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject… | ||
| CVE-2026-73043 | Cri | 0.59 | 9.0 | 0.01 | Aug 15, 2026 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template… | ||
| CVE-2026-73042 | Cri | 0.59 | 9.0 | 0.01 | Aug 15, 2026 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements… | ||
| CVE-2026-73041 | Cri | 0.59 | 9.0 | 0.00 | Aug 15, 2026 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an… |
- risk 0.65cvss 10.0epss 0.01
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with…
- risk 0.64cvss 9.8epss 0.01
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter,…
- risk 0.64cvss 9.8epss 0.01
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
- risk 0.62cvss 9.6epss 0.01
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter…
- risk 0.62cvss 9.6epss 0.01
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab…
- risk 0.62cvss 9.6epss 0.01
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true;…
- risk 0.60cvss 9.3epss 0.01
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including…
- risk 0.59cvss 9.1epss 0.01
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location…
- risk 0.59cvss 9.0epss 0.00
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when…
- risk 0.59cvss 9.0epss 0.01
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled,…
- risk 0.59cvss 9.0epss 0.01
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort…
- risk 0.59cvss 9.0epss 0.00
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value,…
- risk 0.59cvss 9.0epss 0.00
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject…
- risk 0.59cvss 9.0epss 0.01
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template…
- risk 0.59cvss 9.0epss 0.01
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements…
- risk 0.59cvss 9.0epss 0.00
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an…
Page 1 of 11