B3log Siyuan Vulnerabilities

8 advisories affecting B3log Siyuan

8

Total CVEs

7

Critical

1

High

CVE-2026-40322

Apr 16, 2026

Critical (9.0)

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the ...

Read Advisory

CVE-2026-34449

Mar 31, 2026

Critical (9.6)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS po...

Read Advisory

CVE-2026-34448

Mar 31, 2026

Critical (9.0)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gall...

Read Advisory

CVE-2026-34585

Mar 31, 2026

High (8.6)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed wi...

Read Advisory

CVE-2026-32938

Mar 20, 2026

Critical (9.9)

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspa...

Read Advisory

CVE-2026-32940

Mar 20, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses d...

Read Advisory

CVE-2026-30869

Mar 10, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By expl...

Read Advisory

CVE-2026-29183

Mar 6, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when typ...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.