Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
A database Template calculation becomes Remote Code Execution on the desktop client, because the sanitizer written for identical template output is never calledGHSA-rwh7-gm74-67h6 published
Aug 1, 2026 by 88250Critical -
Attribute-view column widths are stored without validation and interpolated into style attributes without escaping, allowing stored cross-site scripting in every table cellGHSA-rj55-w3xr-gj62 published
Aug 1, 2026 by 88250Critical -
Unthrottled brute-force of per-notebook Publish password via /api/filetree/authFilePublishAccessGHSA-v362-968x-gp2v published
Aug 1, 2026 by 88250High -
HTTP Basic Auth path in CheckAuth() bypasses the workspace access-code CAPTCHA/lockout, allowing unthrottled remote brute-force of the admin credentialGHSA-w3xh-mmmh-r54v published
Aug 1, 2026 by 88250Critical -
SSTI env/DNS leak via attribute-view Template calculationGHSA-v97v-gxxg-rhmq published
Aug 1, 2026 by 88250Moderate -
Attribute-view select option colors are stored unvalidated and interpolated into style attributes without escaping at eight render sites, allowing stored cross-site scriptingGHSA-m7cc-jh9q-wxg8 published
Aug 1, 2026 by 88250Critical -
Attribute-view field names are stored unescaped and interpolated into option elements without escaping, allowing stored cross-site scripting in the database sort menuGHSA-g3jx-227v-x2x4 published
Aug 1, 2026 by 88250Critical -
A single unsanitized branch in unicode2Emoji turns a document icon into Remote Code Execution on the desktop clientGHSA-vx5w-qrvp-mmcq published
Aug 1, 2026 by 88250Critical -
A parser differential between the WebSocket keepalive exemption and the session quarantine allows unauthenticated access to the broadcast event stream, defeating the fix for GHSA-xp2m-98x8-rpj6GHSA-c8w8-3pqp-wr83 published
Jul 31, 2026 by 88250High -
authFilePublishAccess distinguishes hidden and forbidden documents from public and nonexistent ones, and issues a publish-auth cookie for documents it reports as forbiddenGHSA-4pjg-x8qj-33j5 published
Jul 31, 2026 by 88250Moderate