Vulnerabilidades em siyuan-note

190 resultados
Análise Vexday

O siyuan-note acumula 67 CVEs catalogadas, com 20 classificadas como críticas — volume que merece atenção, especialmente considerando que 29 dessas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. A falha mais frequente é CWE-79 (Cross-Site Scripting), padrão coerente com aplicações de edição de conteúdo que processam entrada de usuário de forma extensiva. Nenhuma CVE consta no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, e a ausência de PoCs públicas reduz a exposição imediata; contudo, a CVE mais perigosa atualmente identificada, CVE-2026-33476, registra EPSS de 0,0326, sinalizando probabilidade não nula de exploração que justifica monitoramento contínuo. Equipes responsáveis por instâncias do siyuan-note devem priorizar a aplicação de correções dado o volume expressivo de vulnerabilidades críticas acumuladas.

CVE-2026-32747MEDIUMSiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secretsEPSS 0.4%CVE-2026-66395CRITICALSiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan ProtocolEPSS 0.4%CVE-2026-59853MEDIUMSiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter)EPSS 0.4%CVE-2026-40259HIGHSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView APIEPSS 0.4%CVE-2026-74799CRITICALSiYuan before 3.7.4 Unauthenticated Debug Endpoint Information DisclosureEPSS 0.4%CVE-2024-55659HIGHSiYuan has an arbitrary file write in the host via /api/asset/uploadEPSS 0.4%CVE-2026-54068MEDIUMSiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconEPSS 0.4%CVE-2026-86712HIGHSiYuan before 3.8.2 Remote Code Execution via ClipboardEPSS 0.4%CVE-2026-74868HIGHSiYuan before 3.7.4 Brute-Force Authentication via Publish ServiceEPSS 0.4%CVE-2026-66396CRITICALSiYuan before v3.7.2 Stored XSS to RCE via title-img IALEPSS 0.4%CVE-2026-73043CRITICALSiYuan before v3.7.4 Remote Code Execution via Template CalculationEPSS 0.4%CVE-2026-85582HIGHSiYuan before v3.8.2 Unbounded Session Creation via Basic AuthEPSS 0.4%CVE-2026-85585HIGHSiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrencyEPSS 0.4%CVE-2026-74798CRITICALSiYuan kernel Path Traversal via database_clean MCP toolEPSS 0.4%CVE-2026-32815MEDIUMSiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information DisclosureEPSS 0.4%CVE-2026-74904HIGHSiYuan before v3.7.4 Missing Authorization via block APIEPSS 0.4%CVE-2026-69086HIGHSiYuan before v3.7.3 Path Traversal via unvalidated avIDEPSS 0.4%CVE-2026-69083CRITICALSiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContentEPSS 0.4%CVE-2026-60084HIGHSiYuan before v3.7.4 Arbitrary File Deletion via removeTemplateEPSS 0.3%CVE-2026-34585HIGHSiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command executionEPSS 0.3%