Vulnerabilidades em siyuan-note

190 resultados
Análise Vexday

O siyuan-note acumula 67 CVEs catalogadas, com 20 classificadas como críticas — volume que merece atenção, especialmente considerando que 29 dessas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. A falha mais frequente é CWE-79 (Cross-Site Scripting), padrão coerente com aplicações de edição de conteúdo que processam entrada de usuário de forma extensiva. Nenhuma CVE consta no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, e a ausência de PoCs públicas reduz a exposição imediata; contudo, a CVE mais perigosa atualmente identificada, CVE-2026-33476, registra EPSS de 0,0326, sinalizando probabilidade não nula de exploração que justifica monitoramento contínuo. Equipes responsáveis por instâncias do siyuan-note devem priorizar a aplicação de correções dado o volume expressivo de vulnerabilidades críticas acumuladas.

CVE-2026-23851HIGHSiYuan Vulnerable to Arbitrary File Read via File Copy FunctionalityEPSS 0.5%CVE-2026-31809MEDIUMSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSSEPSS 0.5%CVE-2026-34449CRITICALSiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet InjectionEPSS 0.5%CVE-2026-33203HIGHSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive BypassEPSS 0.5%CVE-2026-34448CRITICALSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clientEPSS 0.5%CVE-2026-33194MEDIUMSiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /homeEPSS 0.5%CVE-2026-59854MEDIUMSiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspaceEPSS 0.5%CVE-2026-85583HIGHSiYuan before v3.8.2 Path Traversal via symlink in file APIEPSS 0.5%CVE-2026-34605HIGHSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )EPSS 0.5%CVE-2026-59832HIGHSiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.dbEPSS 0.5%CVE-2026-73056CRITICALSiYuan kernel before 3.7.4 Unthrottled Brute-Force via API TokenEPSS 0.4%CVE-2026-31807MEDIUMSiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSSEPSS 0.4%CVE-2026-54759HIGHSiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, leading to arbitrary command execution via SiYuan Electron clientEPSS 0.4%CVE-2025-67488HIGHSiYuan: ZipSlip -> Arbitrary File Overwrite -> RCEEPSS 0.4%CVE-2026-32749HIGHSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file writeEPSS 0.4%CVE-2026-32750MEDIUMSiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notesEPSS 0.4%CVE-2026-73046CRITICALSiYuan before v3.7.4 Authentication Bypass via HTTP Basic AuthEPSS 0.4%CVE-2026-93923HIGHSiYuan through 3.8.4 Stored XSS via Heading Style AttributeEPSS 0.4%CVE-2026-32938CRITICALSiYuan has an Arbitrary File Read in its Desktop Publish ServiceEPSS 0.4%CVE-2026-92986HIGHSiYuan before 3.8.4 Cross-Site Scripting via Document TitleEPSS 0.4%