Vulnerabilities in siyuan-note

190 results
Vexday analysis

O siyuan-note acumula 67 CVEs catalogadas, com 20 classificadas como críticas — volume que merece atenção, especialmente considerando que 29 dessas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. A falha mais frequente é CWE-79 (Cross-Site Scripting), padrão coerente com aplicações de edição de conteúdo que processam entrada de usuário de forma extensiva. Nenhuma CVE consta no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, e a ausência de PoCs públicas reduz a exposição imediata; contudo, a CVE mais perigosa atualmente identificada, CVE-2026-33476, registra EPSS de 0,0326, sinalizando probabilidade não nula de exploração que justifica monitoramento contínuo. Equipes responsáveis por instâncias do siyuan-note devem priorizar a aplicação de correções dado o volume expressivo de vulnerabilidades críticas acumuladas.

CVE-2024-55657HIGHSiYuan has an arbitrary file read via /api/template/renderEPSS 0.7%CVE-2026-34448CRITICALSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clientEPSS 0.7%CVE-2026-86712HIGHSiYuan before 3.8.2 Remote Code Execution via ClipboardEPSS 0.7%CVE-2026-32767CRITICALSiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search APIEPSS 0.7%CVE-2026-29183CRITICALSiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript executionEPSS 0.7%CVE-2026-33066MEDIUMSiYuan has Stored XSS to RCE via Unsanitized Bazaar README RenderingEPSS 0.7%CVE-2026-25992HIGHSiYuan has a File Read Interface Case Bypass VulnerabilityEPSS 0.7%CVE-2026-33067MEDIUMSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package MetadataEPSS 0.7%CVE-2026-39846CRITICALSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsEPSS 0.7%CVE-2026-73043CRITICALSiYuan before v3.7.4 Remote Code Execution via Template CalculationEPSS 0.6%CVE-2026-85583HIGHSiYuan before v3.8.2 Path Traversal via symlink in file APIEPSS 0.6%CVE-2026-33670CRITICALSiYuan has directory traversal within its publishing serviceEPSS 0.6%CVE-2024-55660MEDIUMSiYuan has an SSTI via /api/template/renderSprigEPSS 0.6%CVE-2026-55570CRITICALSiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (Bypass for CVE-2026-45375's patch)EPSS 0.6%CVE-2026-23850HIGHSiYuan vulnerable to arbitrary file readEPSS 0.6%CVE-2024-55658HIGHSiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesEPSS 0.6%CVE-2026-34605HIGHSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )EPSS 0.6%CVE-2025-21609HIGHSiYuan has an arbitrary file deletion vulnerabilityEPSS 0.6%CVE-2026-93923HIGHSiYuan through 3.8.4 Stored XSS via Heading Style AttributeEPSS 0.6%CVE-2026-85584HIGHSiYuan before v3.8.2 Denial of Service via Auth ThrottleEPSS 0.6%