These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-73054 is an authentication bypass vulnerability in the SiYuan WebSocket endpoint. The vulnerability is caused by differential parsing of query parameters between authentication exemption and session quarantine checks, allowing unauthenticated attackers to craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T22:16:55.157Z and has not been modified since then. The unicode2Emoji function in SiYuan versions before v3.7.4 fails to sanitize codepoint branch output, allowing for cross-site scripting attacks that can lead to arbitrary code execution on the host system. Users of SiYuan versions before v3.7.4 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T22:16:55.017Z and has not been modified since then. The NVD entry is currently Deferred. This critical vulnerability in SiYuan before v3.7.4 results from storing attribute-view field names without HTML escaping and interpolating them directly into option elements via innerHTML in the sort menu. T [truncated]
CVE-2026-73050: SiYuan versions before v3.7.4 are vulnerable to stored cross-site scripting via the color field in attribute-view select options. This critical vulnerability, with a CVSS score of 9.4, allows attackers to inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field. Organizations [truncated]
A local, unauthenticated attacker can inject a malicious Template calculation formula to read environment variables and perform DNS lookups in the attribute-view Template calculation feature of siyuan versions <= 3.7.3. The vulnerability is due to the feature's template engine using Sprig's unmodified function map, which still exposes the env, expandenv, and getHostByName functions that were removed elsew [truncated]
The SiYuan application before version 3.7.4 has a critical authentication bypass vulnerability due to improper restrictions on excessive authentication attempts in the CheckAuth() middleware. This vulnerability allows unauthenticated remote attackers to brute-force the admin access code with unlimited automated requests, potentially leading to full RoleAdministrator access to the kernel. The HTTP Basic Au [truncated]
CVE-2026-73045 is a HIGH-rated vulnerability in SiYuan before 3.7.4 that allows unauthenticated attackers to brute-force per-notebook publish passwords via the authFilePublishAccess endpoint without rate limiting or CAPTCHA. The vulnerability has a CVSS score of 8.7 and is rated HIGH. Affected product deployments should be reviewed for exposure, and compensating controls should be assessed. Security teams [truncated]
The CVE-2026-73044 vulnerability in SiYuan versions before v3.7.4 allows for stored cross-site scripting (XSS) attacks via table column width values. This critical vulnerability enables attackers to inject malicious payloads through the setAttrViewColWidth API, breaking out of style attributes and injecting event handlers on every table cell, executing arbitrary code in the Electron renderer with Node int [truncated]
CVE-2026-73043 is a critical remote code execution vulnerability in SiYuan versions before v3.7.4. The vulnerability is related to the template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, [truncated]
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
The CVE-2026-73041 vulnerability affects SiYuan versions before v3.7.4, allowing attackers to inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF. This critical vulnerability, with a CVSS score of 9.4, is caused by a failure to validate or escape annotation fields written to disk by the setFileAnnotation endp [truncated]
The CVE-2026-73630 vulnerability is an information disclosure issue in SiYuan before version 3.7.4, affecting the /api/filetree/authFilePublishAccess endpoint. This endpoint, registered with CheckAuth only, is reachable anonymously and can be exploited to determine the existence of documents an attacker is not permitted to access. The vulnerability allows an anonymous attacker to distinguish between publi [truncated]
The CVE-2026-73049 record indicates an information disclosure vulnerability in SiYuan versions before v3.7.4. This vulnerability affects users of SiYuan, particularly those with publicly accessible databases or documents. The getAttributeViewBacklinks endpoint improperly filters backlinks, allowing anonymous readers to discover hidden-tier documents by supplying a publicly visible database row identifier. [truncated]
The CVE-2026-72812 record describes a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint of SiYuan versions before v3.7.4. This vulnerability allows anonymous readers to trigger persistent server-side writes, potentially leading to resource amplification attacks by flushing transaction queues, scanning all references globally, and enqueuing database writes, bypassing read-only pr [truncated]
A SQL injection vulnerability exists in SiYuan versions <= v3.7.2 in the backlink/mention search query. The vulnerability allows an attacker to execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4. This issue affects users of SiYuan versions <= v3.7.2, administrators of SiYuan installations, security teams monitoring for SQL injection attacks, and operators of affected platforms. [truncated]
The SiYuan publish-boundary bypass vulnerability (CVE-2026-72810) allows anonymous readers to receive unfiltered edits via WebSocket broadcast sessions. This critical vulnerability has a CVSS score of 9.2 and affects SiYuan versions before v3.7.4. The vulnerability is related to the publish-boundary bypass in WebSocket broadcast sessions, which could allow unauthorized access to sensitive content. Users o [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:25.607Z and has not been modified since then. CVE-2026-73610 is an information disclosure vulnerability in SiYuan before v3.7.4. The local storage filter returns the administrator's entire storage map with only three keys sanitized, allowing unauthenticated attackers or publish readers to r [truncated]
The CVE-2026-73608 vulnerability affects SiYuan's development branch, specifically the /api/av/getAttributeViewSearchTarget endpoint. This endpoint lacks proper authorization checks, allowing an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:53.110Z and has not been modified since then. CVE-2026-72809 is an authentication bypass vulnerability in SiYuan versions <= v3.7.2, patched in v3.7.4. The vulnerability exists in the kernel's CheckAuth function, which grants the administrator role to requests from loopback (127.0.0.1) for [truncated]
CVE-2026-72807 is a second-order SQL injection vulnerability in SiYuan versions before v3.7.4. The vulnerability is located in attribute-view template columns, which expose the queryBlocks function. This function executes raw SQL using string substitution instead of parameterized queries. Attackers can exploit this by distributing malicious SiYuan documents or packages with crafted template columns. When [truncated]
The CVE-2026-72806 record indicates that SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter. This filter fails to check publish password protection when rendering attribute views and database rows, allowing unauthenticated readers to access password-protected document rows, including titles, block IDs, and column values, by calling renderAt [truncated]
SiYuan versions before v3.7.4 have a vulnerability that allows disclosure of protected document content and metadata. The vulnerability exists in the getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, which fail to enforce publish-access checks. This allows anonymous readers or publish RoleReader accounts to retrieve document titles, ancestor block content snippets, reference text, and path [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:52.247Z and has not been modified since then. This vulnerability impacts SiYuan users and administrators who need to ensure proper access controls are in place for the getBlockAttrs and batchGetBlockAttrs endpoints. The vulnerability allows attackers to retrieve block attributes including n [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:52.110Z and has not been modified since then. The CVE-2026-72802 vulnerability affects SiYuan versions before v3.7.4. It is caused by the resolveAssetPath endpoint returning absolute filesystem paths unmodified to CheckAuth-only requests. An attacker can exploit this by harvesting relative [truncated]
The CVE-2026-72801 vulnerability affects SiYuan versions before v3.7.4, allowing unauthenticated access to encrypted-notebook key-derivation material and wrapped data keys through publish mode endpoints. This could enable attackers to perform unlimited offline master-password cracking without rate limiting. Organizations should be aware of the potential vulnerability and take steps to upgrade or mitigate [truncated]
Authenticated readers can exploit SiYuan versions before v3.7.4 to retrieve complete database column schemas and enumerate workspace-wide block IDs without publish scoping. This vulnerability allows attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents, potentially leading to information disclosure.
SiYuan versions before v3.7.4 are vulnerable to improper filtering of related-database content, allowing unauthorized access to sensitive information. The vulnerability has a CVSS score of 9.2 and is classified as CRITICAL. Affected users should assess their exposure, review vendor guidance, and plan for remediation or mitigation. The CVE record was published on 2026-08-12T20:17:51.543Z and has not been m [truncated]
The CVE-2026-72797 record indicates that SiYuan versions before v3.7.4 have an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint. This vulnerability allows anonymous readers and publish-mode accounts to enumerate all encrypted notebooks and their current unlock status, potentially revealing sensitive notebook names and decryption state in memory. The affected product is SiYua [truncated]
The SiYuan application prior to v3.7.4 contains an access control bypass vulnerability. This vulnerability allows attackers to bypass publish-access controls enforced on the REST API by directly accessing static-file routes in the server mux. As a result, attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts. The vulnerability is [truncated]
SiYuan versions before v3.7.4 are vulnerable to unauthorized access due to a failure in filtering embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. This allows attackers to read content from password-protected, hidden, or forbidden documents without authorization. The CVE record was published on 2026-08-12T20:17:51.137Z and has not been modified sinc [truncated]