Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SiYuan Desktop Notification XSS Leads to Electron RCEGHSA-grjj-6f6g-cq8q published
Apr 16, 2026 by 88250High -
Incomplete fix for CVE-2026-33066: XSS in github.com/siyuan-note/siyuanGHSA-8q5w-mmxf-48jg published
Apr 13, 2026 by 88250Moderate -
SiYuan Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCEGHSA-x63q-3rcj-hhp5 published
Apr 11, 2026 by 88250Critical -
Arbitrary File Deletion via Path Traversal in `removeUnusedAttributeView`GHSA-vw86-c94w-v3x4 published
Apr 10, 2026 by 88250High -
Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`GHSA-7m5h-w69j-qggg published
Apr 10, 2026 by 88250High -
Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsGHSA-phhp-9rm9-6gr2 published
Apr 7, 2026 by 88250Critical -
Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram RenderingGHSA-w95v-4h65-j455 published
Apr 9, 2026 by 88250High -
Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )GHSA-73g7-86qr-jrg3 published
Mar 30, 2026 by 88250High -
Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked contentGHSA-c77m-r996-jr3q published
Mar 28, 2026 by 88250High -
Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet InjectionGHSA-68p4-j234-43mv published
Mar 28, 2026 by 88250Critical