Vulnerabilities in siyuan-note

190 results
Vexday analysis

O siyuan-note acumula 67 CVEs catalogadas, com 20 classificadas como críticas — volume que merece atenção, especialmente considerando que 29 dessas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. A falha mais frequente é CWE-79 (Cross-Site Scripting), padrão coerente com aplicações de edição de conteúdo que processam entrada de usuário de forma extensiva. Nenhuma CVE consta no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, e a ausência de PoCs públicas reduz a exposição imediata; contudo, a CVE mais perigosa atualmente identificada, CVE-2026-33476, registra EPSS de 0,0326, sinalizando probabilidade não nula de exploração que justifica monitoramento contínuo. Equipes responsáveis por instâncias do siyuan-note devem priorizar a aplicação de correções dado o volume expressivo de vulnerabilidades críticas acumuladas.

CVE-2026-65607HIGHSiYuan before v3.7.2 Path Traversal via /export/temp/EPSS 0.6%CVE-2026-54069CRITICALSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin AllowlistEPSS 0.6%CVE-2026-85580HIGHSiYuan before v3.8.2 Path Guard Bypass via Case MismatchEPSS 0.6%CVE-2026-85581HIGHSiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registrationEPSS 0.6%CVE-2026-33203HIGHSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive BypassEPSS 0.6%CVE-2026-32749HIGHSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file writeEPSS 0.6%CVE-2026-31809MEDIUMSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSSEPSS 0.6%CVE-2026-66395CRITICALSiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan ProtocolEPSS 0.6%CVE-2026-32938CRITICALSiYuan has an Arbitrary File Read in its Desktop Publish ServiceEPSS 0.6%CVE-2026-44670CRITICALSiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuanEPSS 0.6%CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.6%CVE-2026-60084HIGHSiYuan before v3.7.4 Arbitrary File Deletion via removeTemplateEPSS 0.5%CVE-2026-74799CRITICALSiYuan before 3.7.4 Unauthenticated Debug Endpoint Information DisclosureEPSS 0.5%CVE-2026-66396CRITICALSiYuan before v3.7.2 Stored XSS to RCE via title-img IALEPSS 0.5%CVE-2026-54067CRITICALSiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()EPSS 0.5%CVE-2026-73054HIGHSiYuan before v3.7.4 Authentication Bypass via WebSocketEPSS 0.5%CVE-2026-72810CRITICALSiYuan before v3.7.4 Publish-Boundary Bypass via WebSocketEPSS 0.5%CVE-2026-40259HIGHSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView APIEPSS 0.5%CVE-2026-68584CRITICALSiYuan before v3.7.3 Authentication Bypass via Content EndpointsEPSS 0.5%CVE-2026-69086HIGHSiYuan before v3.7.3 Path Traversal via unvalidated avIDEPSS 0.5%