Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: siyuan Clear
ID Title
CVE-2026-39846 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846). Successful exploitation can lead to full system takeover. Exploitable via ``nodeIntegration``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
CVE-2026-34453 Authorization Flaw in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453). Confidential information can be exposed externally. Exploitable via `POST /api/bookmark/getBookmark`. Mitigation: upgrade to `3.6.2` or later.
CVE-2026-34448 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
CVE-2026-34449 Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449). Successful exploitation can lead to full system takeover. Exploitable via ``Origin``. Mitigation: upgrade to `3.6.2` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →