Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS / RCE via `setBlockAttrs` icon attribute (bypass of dynamic icon XSS fix #15970)GHSA-7c6g-g2hx-23vv published
Jan 18, 2026 by 88250High -
RCE via zip slip and Command Injection via PandocBinGHSA-4r66-7rcv-x46x published
Dec 8, 2025 by 88250High -
Arbitrary file ReadGHSA-cv54-7wv7-qxcw published
Jan 18, 2026 by 88250Critical -
ZipSlip -> Arbitrary File Overwrite -> RCEGHSA-gqfv-g4v7-m366 published
Dec 8, 2025 by 88250High -
Arbitrary file deletion vulnerabilityGHSA-8fx8-pffw-w498 published
Jan 3, 2025 by 88250High -
SSTI via /api/template/renderSprigGHSA-4pjc-pwgq-q9jp published
Dec 11, 2024 by 88250Moderate -
Arbitrary file write in the host via /api/asset/uploadGHSA-fqj6-whhx-47p7 published
Dec 11, 2024 by 88250High -
Arbitrary file read and path traversal via /api/export/exportResourcesGHSA-25w9-wqfq-gwqx published
Dec 11, 2024 by 88250High -
Arbitrary file read via /api/template/renderGHSA-xx68-37v4-4596 published
Dec 11, 2024 by 88250High