Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)GHSA-p23f-cm6q-2qp8 published
Aug 13, 2026 by 88250Moderate -
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)GHSA-x8gv-g2g3-65fj published
Aug 13, 2026 by 88250High -
Incomplete fix for GHSA-qq8m-8p8v-x4xg: IPv6 transition addresses (NAT64/6to4/Teredo) still bypass both SSRF guardsGHSA-rg26-cg95-gq6p published
Aug 10, 2026 by 88250High -
Unescaped URL concatenation into evaluateJavaScript allows JavaScript injection via the `siyuan://` custom URL schemeGHSA-7ffh-xpqv-mh58 published
Aug 10, 2026 by 88250Critical -
Secret placeholders in the http_request MCP tool are interpolated into the destination URL, enabling exfiltration of stored secrets to any attacker-chosen hostGHSA-853m-gvvm-6rvx published
Aug 8, 2026 by 88250Moderate -
Title: MCP file tool's blocklist is incomplete relative to the HTTP file API it claims to align with, exposing publish-mode passwords and other sensitive workspace filesGHSA-c8r8-95hg-mp34 published
Aug 8, 2026 by 88250Moderate -
Missing consistency check between packageName and repoURL/repoHash in bazaar package install allows overwriting an existing, trusted pluginGHSA-rpx2-p6hp-x5gj published
Aug 8, 2026 by 88250Moderate -
Path Traversal via unvalidated packageName across all 10 Bazaar install/uninstall endpoints, enabling arbitrary-location file write (install) and arbitrary recursive directory deletion (uninstall)GHSA-wr4w-7vjm-mmx3 published
Aug 7, 2026 by 88250Critical