Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS in notebook configuration via unescaped template pathsGHSA-v6wf-r2gr-rrgf published
Aug 26, 2026 by 88250Critical -
Stored XSS in Bazaar package cards via unescaped iconURL metadataGHSA-rvcf-q4h8-w6c9 published
Aug 26, 2026 by 88250Critical -
Stored XSS in Search Assets result rows via unescaped asset filenamesGHSA-qcw6-qm34-28h8 published
Aug 26, 2026 by 88250Critical -
Stored XSS in Search Asset Preview via Unescaped Indexed Asset ContentGHSA-64gp-333q-mq6j published
Aug 26, 2026 by 88250Critical -
Path traversal in /api/riff/removeRiffDeck allows admin to delete arbitrary .deck/.cards files outside the workspaceGHSA-94vh-rpgr-rpwc published
Aug 26, 2026 by 88250High -
Reader Can Enumerate Private Attribute-View Key DefinitionsGHSA-j4qq-w6qx-6839 published
Aug 21, 2026 by 88250Moderate -
Published Attribute-View Rows Retain Hidden KeyValuesGHSA-vc7j-5f5p-3x75 published
Aug 21, 2026 by 88250Moderate -
Reader can read files from an explicitly hidden notebookGHSA-8ggq-wq3f-vxrw published
Aug 21, 2026 by 88250Moderate -
Reader-role undoState discloses private related document root IDsGHSA-6gf8-q9ch-w732 published
Aug 21, 2026 by 88250Moderate -
Linux MCP publish-access path guard bypass exposes publishAccess.jsonGHSA-mmgw-3mx9-cfwp published
Aug 21, 2026 by 88250Moderate