PatchSiren

SiYuan CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL SiYuan CVE published 2026-08-17

CVE-2026-74798

The CVE record for CVE-2026-74798 was published on 2026-08-17T11:16:39.873Z and has not been modified since then. The vulnerability affects SiYuan kernel versions before v3.7.4 and allows an authenticated MCP client to read and delete arbitrary files through a path traversal vulnerability in the database_clean MCP tool. Users of affected versions should take immediate action to mitigate the vulnerability. [truncated]

CRITICAL SiYuan CVE published 2026-06-21

CVE-2026-56397

CVE-2026-56397 is a critical vulnerability in SiYuan before v3.6.1. The issue allows malicious package authors to inject arbitrary HTML and JavaScript into package metadata and README content in the Bazaar marketplace. This can lead to remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields. The vulnerability exploits Electron's [truncated]

CRITICAL SiYuan CVE published 2026-06-21

CVE-2026-56395

CVE-2026-56395 is a critical vulnerability in SiYuan before v3.6.1. The issue allows malicious package authors to inject arbitrary HTML and JavaScript into package metadata and README content in the Bazaar marketplace. This enables attackers to achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields. The vulnerability ex [truncated]