Vulnerabilities in siyuan-note

190 results
Vexday analysis

O siyuan-note acumula 67 CVEs catalogadas, com 20 classificadas como críticas — volume que merece atenção, especialmente considerando que 29 dessas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. A falha mais frequente é CWE-79 (Cross-Site Scripting), padrão coerente com aplicações de edição de conteúdo que processam entrada de usuário de forma extensiva. Nenhuma CVE consta no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, e a ausência de PoCs públicas reduz a exposição imediata; contudo, a CVE mais perigosa atualmente identificada, CVE-2026-33476, registra EPSS de 0,0326, sinalizando probabilidade não nula de exploração que justifica monitoramento contínuo. Equipes responsáveis por instâncias do siyuan-note devem priorizar a aplicação de correções dado o volume expressivo de vulnerabilidades críticas acumuladas.

CVE-2026-33194MEDIUMSiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /homeEPSS 0.5%CVE-2026-59854MEDIUMSiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspaceEPSS 0.5%CVE-2026-87815HIGHSiYuan before v3.8.2 Path Traversal via removeRiffDeckEPSS 0.5%CVE-2026-82651MEDIUMSiYuan before v3.8.1 Missing Authorization via /history and /repo/diffEPSS 0.5%CVE-2026-29073MEDIUMSiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database accessEPSS 0.5%CVE-2026-69083CRITICALSiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContentEPSS 0.5%CVE-2026-66394CRITICALSiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer BypassEPSS 0.5%CVE-2026-32750MEDIUMSiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notesEPSS 0.5%CVE-2026-59832HIGHSiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.dbEPSS 0.5%CVE-2026-41894HIGHSiYuan: Incomplete Fix Bypass for CVE-2026-30869: Path Traversal via Double URL Encoding in `/export/` EndpointEPSS 0.5%CVE-2026-32940CRITICALSiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)EPSS 0.5%CVE-2026-40107HIGHSiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram RenderingEPSS 0.5%CVE-2026-87807HIGHsiyuan before v3.8.2 SQL Injection via fullTextSearchBlockEPSS 0.5%CVE-2026-54759HIGHSiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, leading to arbitrary command execution via SiYuan Electron clientEPSS 0.4%CVE-2026-87808HIGHSiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlockEPSS 0.4%CVE-2025-67488HIGHSiYuan: ZipSlip -> Arbitrary File Overwrite -> RCEEPSS 0.4%CVE-2026-40318HIGHSiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`EPSS 0.4%CVE-2026-72811CRITICALSiYuan before v3.7.4 SQL Injection via backlink searchEPSS 0.4%CVE-2026-85582HIGHSiYuan before v3.8.2 Unbounded Session Creation via Basic AuthEPSS 0.4%CVE-2026-72798CRITICALSiYuan before v3.7.4 Information Disclosure via renderAttributeViewEPSS 0.4%