These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-85175 debrief based on the supplied source corpus. The CVE record was published on 2026-10-05T17:32:48.000Z and has not been modified since then. The vulnerability allows authenticated users to retrieve TLS private keys via the `getFile` API due to an incomplete blocklist in `IsForbiddenAbsPath()`. Defenders should verify exposure, assess impact, and implement compensating controls. The `IsForbid [truncated]
CVE-2026-82651: SiYuan Historical Snapshot Exposure. Affected product: SiYuan versions before v3.8.1. Vulnerability class: Missing authorization checks. Likely operational impact: Authenticated administrators may retrieve historical snapshots of sensitive files. Source-confidence limits: Limited evidence; further verification required. Review context: Administrators and users should review system configur [truncated]
CVE-2026-105205 is an information disclosure vulnerability in SiYuan before 3.8.5. Publish-mode readers can learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. This vulnerability allows attackers to bypass the publish confidentiality boundary, potentially leading to unauthorized access to sensitive information. Defenders of [truncated]
CVE-2026-82234 debrief based on the supplied source corpus. The CVE record was published on 2026-10-02T23:17:16.000Z and has not been modified since then. The SiYuan Agent Tools are vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS-Rebinding TOCTOU (Time-of-Check-to-Time-of-Use) due to a bypass of the CheckHostSSRF mechanism. This vulnerability affects SiYuan versions <= 3.8.0 and is patch [truncated]
The SiYuan MCP `asset.upload` function reads arbitrary absolute file paths, bypassing workspace boundaries. This vulnerability is residual from CVE-2026-66012 and affects SiYuan versions <= 3.8.0. The patched version is 3.8.1. Defenders should assess exposure and prioritize verification and remediation efforts. The vulnerability requires AI Agent invocation of `asset.upload` and user approval, with a low [truncated]
The CVE record was published on 2026-10-02T23:05:33.000Z and has not been modified since then. The NVD entry is currently HIGH. Defenders responsible for SiYuan deployments, especially those with anonymous publish-mode readers, should assess exposure and prioritize verification and potential compensating controls. This vulnerability is caused by 17 handlers in `kernel/api/block.go` having no access checks [truncated]
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attacker-chos [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:25.043Z and has not been modified since then. The NVD entry is currently Deferred. CVE-2026-73606 is an information disclosure vulnerability in SiYuan versions before v3.7.4. The vulnerability exists in the /api/block/getRefIDs endpoint, which fails to check password-protected document tier [truncated]
CVE-2026-73609 debrief based on the supplied source corpus. The CVE record was published on 2026-10-01T16:23:37.000Z and has not been modified since then. This vulnerability affects SiYuan installations, particularly those with anonymous reader access enabled. Defenders should assess the potential impact and implement necessary mitigations. The `/api/attr/getBookmarkLabels` endpoint returns every bookmark [truncated]
CVE-2026-73607 debrief based on the supplied source corpus. The CVE record was published on 2026-10-01T15:44:46.000Z and has not been modified since then. The NVD entry is currently Medium. This vulnerability affects SiYuan's /api/storage/getOutlineStorage endpoint, which lacks authorization checks, potentially allowing unauthorized access to sensitive document outlines. Defenders should assess exposure a [truncated]
CVE-2026-72788 debrief: SiYuan discloses an administrator's open documents and search terms to anonymous readers due to defects in `FilterConfByPublishIgnore`. The vulnerability allows an attacker to obtain sensitive information about the administrator's workspace, including open password-protected documents, locked or closed notebooks, recent search terms, and private assets. Defenders and administrators [truncated]
Unauthenticated SQL injection vulnerability in SiYuan's searchDocs endpoint allows read and write access across all non-encrypted notebooks. The endpoint concatenates user-supplied search keywords directly into SQL statements without proper escaping or parameter binding, allowing attackers to execute stacked SQL statements. This vulnerability affects SiYuan users, administrators, and security teams, who s [truncated]
CVE-2026-100640 is a high-severity vulnerability in SiYuan before version 3.8.4, allowing remote kernel renderers to access native clipboard formats via IPC. This issue, caused by an authorization omission in the siyuan-get IPC handler, enables attackers to obtain MathML formulas, Office bytes, and WPS bytes from the local clipboard during user-mediated paste operations.
CVE-2026-100635 debrief: SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie. The CVE record was published on 2026-09-26T13:23:09.854Z and has not been modified since then. The NVD entry is currently 8.2 HIGH. Defenders should assess exposure, particularly those managing SiYuan deployments, as an on-path attacker can replay a valid publish-visitor-session-id cookie to access authentica [truncated]
CVE-2026-87815 debrief based on the supplied source corpus. The CVE record was published on 2026-09-09T12:17:16.537Z and was last modified on 2026-09-14T14:17:17.650Z. The NVD entry is currently Deferred. Defenders responsible for SiYuan deployments should assess exposure and prioritize patching, as an authenticated administrator can exploit this vulnerability to delete arbitrary files. This vulnerability [truncated]
CVE-2026-87814 is a stored cross-site scripting vulnerability in SiYuan before v3.8.2. The vulnerability affects the search asset preview feature, allowing attackers to execute JavaScript in the SiYuan origin when victims preview assets. This vulnerability can lead to unauthorized actions and workspace manipulation. Defenders should assess exposure and prioritize verification and remediation efforts to pr [truncated]
CVE-2026-87810 is an information disclosure vulnerability in Siyuan before v3.8.2, affecting the POST /api/search/fullTextSearchBlock endpoint. This vulnerability allows unauthenticated publish-mode readers to submit arbitrary search terms and learn whether matching content exists in hidden or unpublished documents, determining the number of matching blocks and pages.
CVE-2026-87809 debrief: Siyuan fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints, allowing attackers with reader access to retrieve full rendered content of private, hidden, or publish-disabled blocks via public documents containing embed queries. This vulnerability affects Siyuan instances with public documents c [truncated]
The SiYuan application prior to v3.8.1 contains a stored XSS vulnerability due to improper escaping of block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. This vulnerability allows attackers to inject HTML/script tags into a block's name, which will execute when another user views documents referencing or displaying that block. The CVE record was published on 2026-08- [truncated]
The SiYuan application prior to v3.8.1 contains a stored cross-site scripting vulnerability in the confirmDialog() function. This vulnerability allows attackers to inject malicious HTML/script payloads through unescaped package names and notebook names, which are directly interpolated into innerHTML assignments. The vulnerability was publicly disclosed on 2026-08-30T15:16:46.033Z. Users of SiYuan prior to [truncated]
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted. This vulnerability impacts SiYuan deployments with configured invisible content, potentially leading to information [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T15:16:45.610Z and has not been modified since then. CVE-2026-82650 is a Medium-severity vulnerability in SiYuan 3.8.0, allowing authenticated attackers to read sensitive workspace files via the RenderTemplate function in kernel/model/template.go, reachable through the POST /api/template/render en [truncated]
The SiYuan Windows installer before version 3.8.1 contains an uncontrolled search path element vulnerability. This vulnerability allows an attacker to execute a malicious executable with elevated privileges, potentially leading to local privilege escalation. The vulnerability is caused by the NSIS installer's use of an uncontrolled search path element, which allows an attacker to execute a malicious execu [truncated]
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. This vulnerability enables attackers with admin access to write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted pa [truncated]
The SiYuan application through version 3.7.3 contains a critical cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. This vulnerability allows an attacker to inject a self-firing payload that can execute automatically when a victim types '((' followed by a search term that surfaces the crafted block. The payload can lead to arbitrary OS command execution due to Electron [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T12:19:30.780Z and has not been modified since then. The NVD entry is currently Deferred. The SiYuan application before v3.7.4 contains a server-side request forgery (SSRF) vulnerability. The isPrivateIP function in kernel/util/net.go does not properly recognize IPv6 transition addresses (NAT64, 6 [truncated]
The CVE-2026-74903 record indicates an insufficient access control vulnerability in SiYuan before v3.7.4, specifically in the /api/lute/spinBlockDOM endpoint. Authenticated users with RoleEditor or RoleReader roles can invoke the endpoint to transform arbitrary DOM input, potentially leading to endpoint starvation through large payloads. This issue has a CVSS score of 5.3 and a MEDIUM severity. Users of S [truncated]
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T11:16:40.187Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects SiYuan installations before version 3.7.4, allowing authenticated attackers to upload HTML files as assets. When a workspace owner opens the asset link, the uploaded HTML content ca [truncated]
CVE-2026-74799 is a critical vulnerability in SiYuan, a note-taking application. When the --mode flag is not set to exactly prod, SiYuan registers Go net/http/pprof debug endpoints, including heap and goroutine dumps, without authentication. This allows attackers to access /debug/pprof/heap and related endpoints to extract in-memory secrets, such as AccessAuthCode and AI provider API keys. The vulnerabili [truncated]