PatchSiren

siyuan-note CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL siyuan-note CVE published 2026-08-12

CVE-2026-72794

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:50.977Z and has not been modified since then. The NVD entry is currently Deferred. Organizations and users of siyuan versions before v3.7.4 should be aware of this vulnerability and take steps to mitigate it. This includes reviewing their deployments, restricting access to the /api/system/g [truncated]

CRITICAL siyuan-note CVE published 2026-08-12

CVE-2026-72793

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:50.837Z and has not been modified since then. The NVD entry is currently Deferred. SiYuan versions before v3.7.4 are vulnerable to information disclosure via the /api/system/getConf endpoint, exposing session-cookie signing key, OS username, and encrypted-notebook key material. This allows [truncated]

MEDIUM siyuan-note CVE published 2026-08-12

CVE-2026-72792

The CVE-2026-72792 record indicates an information disclosure vulnerability in SiYuan before v3.7.4, specifically in the /api/tag/getTag endpoint. This endpoint returns tag labels and occurrence counts from password-protected documents to unauthenticated readers, potentially allowing attackers to enumerate tag vocabulary and internal terminology. Affected product deployments should be reviewed for exposur [truncated]

MEDIUM siyuan-note CVE published 2026-08-12

CVE-2026-72791

CVE-2026-72791 is an information disclosure vulnerability in SiYuan v3.7.4-alpha.1 pre-release version. The /api/av/getAttributeViewFieldViews endpoint allows reader-role callers to retrieve the complete database view structure for any database whose avID is supplied, regardless of authorization. This issue was introduced by commit acfc02ee8 and fixed in v3.7.4. Users of SiYuan v3.7.4-alpha.1 pre-release [truncated]

MEDIUM siyuan-note CVE published 2026-08-12

CVE-2026-72790

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:50.407Z and has not been modified since then. The NVD entry is currently Deferred. This information disclosure vulnerability in SiYuan before v3.7.4 affects users with notebook deployments, as it allows unauthorized access to notebook metadata, potentially exposing sensitive information abo [truncated]

CRITICAL siyuan-note CVE published 2026-07-27

CVE-2026-66395

CVE-2026-66395 is a reflected cross-site scripting vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. This vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that e [truncated]

CRITICAL siyuan-note CVE published 2026-07-27

CVE-2026-66394

CVE-2026-66394 is a critical vulnerability in SiYuan before v3.7.3, enabling authenticated attackers to execute scripts via stored and reflected cross-site scripting in SVG sanitization. The vulnerability exists in SiYuan's SVG sanitization process, where attackers can bypass the HTML parser-based cleaner by hiding script tags within desc, style, or noscript elements. Users of SiYuan versions prior to v3. [truncated]

CRITICAL siyuan-note CVE published 2026-07-23

CVE-2026-65606

A critical vulnerability exists in SiYuan before v3.7.2, allowing for cross-site scripting (XSS) via the siyuan:// protocol handler. This can escalate to arbitrary operating-system command execution due to the application's use of nodeIntegration:true in the SiYuan Desktop renderer. The vulnerability is caused by the application's failure to escape the icon parameter in the tab header when handling siyuan [truncated]

CRITICAL siyuan-note CVE published 2026-07-23

CVE-2026-65605

A stored cross-site scripting vulnerability exists in SiYuan before v3.7.2 in Attribute View (database) cell rendering. A Template column value is rendered as HTML without auto-escaping, allowing for payloads like <img src=x onerror=...> to be stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. The desktop renderer runs with nodeIntegration enabled, allo [truncated]

HIGH siyuan-note CVE published 2026-07-23

CVE-2026-65607

CVE-2026-65607 is a path traversal vulnerability in SiYuan before v3.7.2. The vulnerability exists in the /export/temp/ short-circuit branch of the serveExport handler. An authenticated attacker can send percent-encoded traversal sequences to read arbitrary files outside TempDir, potentially leading to sensitive information disclosure. Users of SiYuan before v3.7.2 should apply the patch to prevent exploi [truncated]

HIGH siyuan-note CVE published 2026-07-09

CVE-2026-59855

CVE-2026-59855 is a high-severity vulnerability in SiYuan, an open-source personal knowledge management system. The vulnerability exists in the Asset.render function, located in app/src/asset/index.ts, where the unsanitized this.path value is interpolated into HTML assigned to innerHTML. This allows a crafted asset link containing a double quote to break out of the src attribute and inject an event handle [truncated]

MEDIUM siyuan-note CVE published 2026-07-09

CVE-2026-59854

CVE-2026-59854 is a file exfiltration vulnerability in SiYuan, a personal knowledge management system. An authenticated administrator or API-token user can copy sensitive files through the API. This issue allows attackers to access sensitive information, potentially leading to further exploitation. Users should review their deployment and apply mitigations.

MEDIUM siyuan-note CVE published 2026-07-09

CVE-2026-59853

The CVE-2026-59853 issue was reported in the SiYuan personal knowledge management system. An endpoint vulnerability allowed unauthorized access to private document information for users with publish-mode Reader access. The issue was addressed in version 3.7.1. This vulnerability has a CVSS score of 6.5 and is considered medium severity. Users with publish-mode Reader access may have been exposed to privat [truncated]

HIGH siyuan-note CVE published 2026-07-09

CVE-2026-59834

CVE-2026-59834 is a high-severity vulnerability in the SiYuan open-source personal knowledge management system prior to version 3.7.1. An unauthenticated publish visitor can inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path via the block search endpoint POST /api/search/fullTextSearchBlock. This issue allows an attacker to access sensitive informatio [truncated]

HIGH siyuan-note CVE published 2026-07-09

CVE-2026-59833

CVE-2026-59833 is a stored cross-site scripting vulnerability in SiYuan personal knowledge management system prior to version 3.7.1. The vulnerability allows attackers to execute OS commands in the Electron desktop renderer via document export-preview and Bazaar package README render paths. This issue is caused by the Lute engine's failure to properly sanitize user input, allowing attackers to inject mali [truncated]

HIGH siyuan-note CVE published 2026-07-09

CVE-2026-59832

CVE-2026-59832 is a high-severity vulnerability in SiYuan, an open-source personal knowledge management system. The vulnerability allows an authenticated user to read workspace secrets and the document database due to improper path handling in the /snippets/*filepath route handler. This issue was fixed in version 3.7.1. The vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Users of Si [truncated]