📦 Siyuan

by B3log

🔍 What is Siyuan?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25539

CRITICAL CVSS 9.1 Feb 4, 2026

This vulnerability allows authenticated users of SiYuan personal knowledge management system to write files to arbitrary locations on the filesystem due to improper validation of the dest parameter in...

CVE-2026-23852

CRITICAL CVSS 9.6 Jan 19, 2026

SiYuan personal knowledge management systems before version 3.5.4 have a stored XSS vulnerability in the dynamic icon feature. Attackers can inject malicious HTML attributes via the /api/attr/setBlock...

CVE-2025-21609

CRITICAL CVSS 9.1 Jan 3, 2025

SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability in the POST /api/history/getDocHistoryContent endpoint. Attackers can craft payloads to delete arbitrary files on the server, po...

CVE-2024-55660

CRITICAL CVSS 9.8 Dec 12, 2024

This CVE describes a Server-Side Template Injection (SSTI) vulnerability in SiYuan's Sprig template engine that allows attackers to access environment variables. Attackers can exploit the /api/templat...

CVE-2024-53504

CRITICAL CVSS 9.8 Nov 29, 2024

A SQL injection vulnerability in Siyuan 3.1.11 allows attackers to execute arbitrary SQL commands via the notebook parameter in the /searchHistory endpoint. This affects all users running vulnerable v...

CVE-2024-53506

CRITICAL CVSS 9.8 Nov 29, 2024

A SQL injection vulnerability in Siyuan 3.1.11 allows attackers to execute arbitrary SQL commands via the ids array parameter in the /batchGetBlockAttrs endpoint. This affects all users running vulner...

CVE-2024-2692

CRITICAL CVSS 9.0 Apr 4, 2024

CVE-2024-2692 is a Server-Side Cross-Site Scripting (XSS) vulnerability in SiYuan note-taking software version 3.0.3 that allows attackers to execute arbitrary commands on the server. This occurs beca...

CVE-2026-23850

HIGH CVSS 7.5 Jan 19, 2026

SiYuan personal knowledge management system versions before 3.5.4 contain a path traversal vulnerability in the markdown feature's HTML rendering. This allows attackers to read arbitrary files on the ...

CVE-2025-68948

HIGH CVSS 8.1 Dec 27, 2025

This vulnerability allows attackers to decrypt session cookies and steal authentication credentials in SiYuan Note software. Attackers who intercept session cookies can extract the AccessAuthCode and ...

CVE-2025-67488

HIGH CVSS 7.8 Dec 9, 2025

This ZipSlip vulnerability in SiYuan personal knowledge management software allows authenticated users to overwrite arbitrary files on the system through the import functionality. Attackers can achiev...

CVE-2024-55657

HIGH CVSS 7.5 Dec 12, 2024

CVE-2024-55657 is an arbitrary file read vulnerability in SiYuan personal knowledge management systems. Attackers can exploit the unvalidated path parameter in the /api/template/render endpoint to rea...

CVE-2026-25647

MEDIUM CVSS 4.6 Feb 6, 2026

CVE-2026-25647 is a stored cross-site scripting (XSS) vulnerability in Lute's Markdown rendering engine that allows attackers to inject malicious JavaScript into Markdown content. When other users vie...

CVE-2026-23847

MEDIUM CVSS 6.1 Jan 19, 2026

SiYuan personal knowledge management systems before version 3.5.4 are vulnerable to reflected cross-site scripting (XSS) via the /api/icon/getDynamicIcon endpoint. Attackers can inject malicious SVG c...

CVE-2026-23851

MEDIUM CVSS 6.5 Jan 19, 2026

This CVE describes a path traversal vulnerability in SiYuan's file copy endpoint that allows authenticated users to copy arbitrary files from the server's filesystem into the application workspace. Th...

CVE-2024-55659

MEDIUM CVSS 5.4 Dec 12, 2024

This vulnerability in SiYuan personal knowledge management systems allows attackers to write arbitrary files to the host server and execute stored cross-site scripting attacks through the file upload ...