Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet InjectionGHSA-68p4-j234-43mv published
Mar 28, 2026 by 88250Critical -
Stored XSS in imported .sy.zip content leads to arbitrary command execution in SiYuan DesktopGHSA-ff66-236v-p4fg published
Mar 29, 2026 by 88250High -
Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clientGHSA-rx4h-526q-4458 published
Mar 28, 2026 by 88250Critical -
Arbitrary document reading within the publishing serviceGHSA-34xj-66v3-6j83 published
Mar 23, 2026 by 88250Critical -
Directory traversal within the publishing serviceGHSA-xmw9-6r43-x9ww published
Mar 23, 2026 by 88250Critical -
Unauthenticated Arbitrary File Read via Path TraversalGHSA-hhgj-gg9h-rjp7 published
Mar 20, 2026 by 88250High -
Unauthenticated WebSocket DoS via Auth Keepalive BypassGHSA-3g9h-9hp4-654v published
Mar 18, 2026 by 88250High -
Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home (GHSA-h5vh-m7fg-w5h6 Bypass)GHSA-vm69-h85x-8p85 published
Mar 18, 2026 by 88250Moderate -
Stored XSS to RCE via Unsanitized Bazaar README RenderingGHSA-4663-4mpg-879v published
Mar 17, 2026 by 88250Critical -
Stored XSS to RCE via Unsanitized Bazaar Package MetadataGHSA-mvpm-v6q4-m2pf published
Mar 17, 2026 by 88250Critical