#Knowledge Management
All CosmicBytez Labs articles tagged #Knowledge Management, across news, security advisories, how-to guides, and projects.
- Security
SiYuan API Token Brute-Force via Missing Rate Limiting — CVE-2026-73056
SiYuan's CheckAuth() middleware has no rate limiting, allowing unauthenticated attackers to brute-force API tokens and gain full admin access (CVSS 9.8).
- Security
CVE-2026-40259 — SiYuan Knowledge Management Authorization
A high-severity authorization bypass in SiYuan versions 3.6.3 and below allows attackers with RoleReader publish-service tokens to call a privileged...
- Security
CVE-2026-40322: SiYuan XSS via Mermaid innerHTML Injection
SiYuan knowledge management versions 3.6.3 and below render Mermaid diagrams with loose security, allowing attacker-controlled javascript: URLs to execute...
- Security
CVE-2026-33669: SiYuan Unauthenticated Document Content
A critical unauthenticated information disclosure vulnerability in SiYuan, the personal knowledge management system, allows remote attackers to retrieve...
- Security
CVE-2026-33670: SiYuan readDir Path Traversal Notebook
A critical path traversal vulnerability in SiYuan's /api/file/readDir interface allows unauthenticated remote attackers to traverse notebook directories...