These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. This vulnerability enables attackers with admin access to write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted pa [truncated]
The SiYuan application through version 3.7.3 contains a critical cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. This vulnerability allows an attacker to inject a self-firing payload that can execute automatically when a victim types '((' followed by a search term that surfaces the crafted block. The payload can lead to arbitrary OS command execution due to Electron [truncated]
CVE-2026-66395 is a reflected cross-site scripting vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. This vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that e [truncated]
CVE-2026-66394 is a critical vulnerability in SiYuan before v3.7.3, enabling authenticated attackers to execute scripts via stored and reflected cross-site scripting in SVG sanitization. The vulnerability exists in SiYuan's SVG sanitization process, where attackers can bypass the HTML parser-based cleaner by hiding script tags within desc, style, or noscript elements. Users of SiYuan versions prior to v3. [truncated]
CVE-2026-65607 is a path traversal vulnerability in SiYuan before v3.7.2. The vulnerability exists in the /export/temp/ short-circuit branch of the serveExport handler. An authenticated attacker can send percent-encoded traversal sequences to read arbitrary files outside TempDir, potentially leading to sensitive information disclosure. Users of SiYuan before v3.7.2 should apply the patch to prevent exploi [truncated]
CVE-2026-59855 is a high-severity vulnerability in SiYuan, an open-source personal knowledge management system. The vulnerability exists in the Asset.render function, located in app/src/asset/index.ts, where the unsanitized this.path value is interpolated into HTML assigned to innerHTML. This allows a crafted asset link containing a double quote to break out of the src attribute and inject an event handle [truncated]
CVE-2026-59854 is a file exfiltration vulnerability in SiYuan, a personal knowledge management system. An authenticated administrator or API-token user can copy sensitive files through the API. This issue allows attackers to access sensitive information, potentially leading to further exploitation. Users should review their deployment and apply mitigations.
The CVE-2026-59853 issue was reported in the SiYuan personal knowledge management system. An endpoint vulnerability allowed unauthorized access to private document information for users with publish-mode Reader access. The issue was addressed in version 3.7.1. This vulnerability has a CVSS score of 6.5 and is considered medium severity. Users with publish-mode Reader access may have been exposed to privat [truncated]
CVE-2026-59834 is a high-severity vulnerability in the SiYuan open-source personal knowledge management system prior to version 3.7.1. An unauthenticated publish visitor can inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path via the block search endpoint POST /api/search/fullTextSearchBlock. This issue allows an attacker to access sensitive informatio [truncated]
CVE-2026-59833 is a stored cross-site scripting vulnerability in SiYuan personal knowledge management system prior to version 3.7.1. The vulnerability allows attackers to execute OS commands in the Electron desktop renderer via document export-preview and Bazaar package README render paths. This issue is caused by the Lute engine's failure to properly sanitize user input, allowing attackers to inject mali [truncated]
CVE-2026-59832 is a high-severity vulnerability in SiYuan, an open-source personal knowledge management system. The vulnerability allows an authenticated user to read workspace secrets and the document database due to improper path handling in the /snippets/*filepath route handler. This issue was fixed in version 3.7.1. The vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Users of Si [truncated]