Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Reader/anonymous SQL injection via unescaped tag in graph.go query2Stmt exfiltrates cross-notebook private dataGHSA-5rwv-4j4c-f954 published
Sep 4, 2026 by 88250High -
Clipboard format spoofing from a web page's copy event bypasses paste sanitization and leads to remote code execution in the desktop appGHSA-9rr9-pxr4-gcgc published
Aug 28, 2026 by 88250High -
Authenticated SQL Injection in full-text search (`method=1` query syntax)GHSA-336w-67gx-gx2h published
Aug 26, 2026 by 88250High -
Incomplete fix for CVE-2026-32767 / GHSA-j7wh-x834-p3r7: `/api/search/fullTextSearchBlock` still bypasses the read-only boundaryGHSA-4qwm-3p58-vh67 published
Aug 26, 2026 by 88250Moderate -
Reader-capable /api/export/preview and /api/lute/copyStdMarkdown expand publish-disabled embeds before publication filteringGHSA-8wx4-fvqw-f5f8 published
Aug 26, 2026 by 88250High -
Publish-mode /api/search/fullTextSearchBlock discloses private-match counts despite returning no private blocksGHSA-g45v-hxvm-wccj published
Aug 26, 2026 by 88250Moderate -
Stored XSS in notebook configuration via unescaped template pathsGHSA-v6wf-r2gr-rrgf published
Aug 26, 2026 by 88250Critical -
Stored XSS in Bazaar package cards via unescaped iconURL metadataGHSA-rvcf-q4h8-w6c9 published
Aug 26, 2026 by 88250Critical -
Stored XSS in Search Assets result rows via unescaped asset filenamesGHSA-qcw6-qm34-28h8 published
Aug 26, 2026 by 88250Critical -
Stored XSS in Search Asset Preview via Unescaped Indexed Asset ContentGHSA-64gp-333q-mq6j published
Aug 26, 2026 by 88250Critical