VYPR

Siyuan

by Siyuan Note

Source repositories

CVEs (198)

  • CVE-2024-55657HigDec 12, 2024
    risk 0.42cvss 7.5epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host…

  • CVE-2026-87814HigSep 9, 2026
    risk 0.40cvss 7.3epss 0.00

    SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute…

  • CVE-2026-87813HigSep 9, 2026
    risk 0.40cvss 7.3epss 0.00

    SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing malicious markup that executes JavaScript in…

  • CVE-2026-87811HigSep 9, 2026
    risk 0.40cvss 7.3epss 0.00

    SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScript when a victim opens notebook…

  • CVE-2026-73047MedAug 15, 2026
    risk 0.40cvss 6.2epss 0.00

    siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1). The feature's template engine uses Sprig's unmodified function map, which still exposes the env,…

  • CVE-2026-82649HigAug 30, 2026
    risk 0.39cvss —epss 0.00

    SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec…

  • CVE-2026-54070HigJun 24, 2026
    risk 0.39cvss 7.1epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute sanitizer is an event-handler blocklist:…

  • CVE-2026-41894HigApr 24, 2026
    risk 0.39cvss —epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause — a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use…

  • CVE-2026-30926HigMar 10, 2026
    risk 0.39cvss 7.1epss 0.00

    SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API…

  • CVE-2026-73630MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never sets a failure code, so its outcome is signalled entirely by the…

  • CVE-2026-73049MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row…

  • CVE-2026-73048MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by…

  • CVE-2026-73610MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. Unauthenticated attackers or publish readers can retrieve closed-tab history, search keywords,…

  • CVE-2026-73609MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark…

  • CVE-2026-73607MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier,…

  • CVE-2026-73606MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain…

  • CVE-2026-73605MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and…

  • CVE-2026-72791MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeViewFieldViews endpoint. The route is registered with CheckAuth only and applies no publish-access…

  • CVE-2026-72788MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms,…

  • CVE-2026-87812MedSep 9, 2026
    risk 0.37cvss 6.8epss 0.00

    SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the…

Page 7 of 10