#SiYuan
All CosmicBytez Labs articles tagged #SiYuan, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-74799: SiYuan pprof Debug Endpoints Exposed Without Authentication
SiYuan before 3.7.4 exposes Go pprof debug endpoints unauthenticated, leaking in-memory secrets including API keys and auth codes.
- Security
CVE-2026-74800: SiYuan Stored XSS via Asset Upload Enables Full Kernel API Access
SiYuan before 3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers, enabling stored XSS with full kernel API access.
- Security
SiYuan API Token Brute-Force via Missing Rate Limiting — CVE-2026-73056
SiYuan's CheckAuth() middleware has no rate limiting, allowing unauthenticated attackers to brute-force API tokens and gain full admin access (CVSS 9.8).
- Security
CVE-2026-73041: SiYuan XSS via PDF Annotation Fields Grants Full Node.js Access
Critical CVSS 9.0 XSS in SiYuan's PDF annotation renderer allows script injection with full Node.js access on affected versions before v3.7.4.
- Security
SiYuan Stored XSS via Database Menu Metadata (CVE-2026-73042)
SiYuan before v3.7.4 fails to escape database menu metadata, enabling stored XSS in group, view, and field-edit menus. CVSS 9.0 Critical.
- Security
CVE-2026-73043: SiYuan RCE via Template Calculation Operator
Critical RCE in SiYuan note-taking app. Unsanitized Go templates allow script injection for all versions before v3.7.4.
- Security
SiYuan Column Width API Stored XSS (CVE-2026-73044)
SiYuan before v3.7.4 allows stored XSS via unescaped table column width values in style attributes. CVSS 9.0 Critical. Patch to v3.7.4.
- Security
SiYuan API Authentication Has No Rate Limiting (CVE-2026-73046)
SiYuan before v3.7.4 has no brute-force protection on its /api/* auth middleware, exposing the workspace to credential stuffing. CVSS 9.8.
- Security
SiYuan Stored XSS via Select Option Color Field (CVE-2026-73050)
SiYuan before v3.7.4 fails to escape the color field in attribute-view select options, enabling stored XSS at eight render sites. CVSS 9.0.
- Security
CVE-2026-72811: SiYuan SQL Injection in Backlink Search Scores Perfect 10.0
SiYuan note-taking app up to v3.7.2 is vulnerable to SQL injection via stored block metadata in the backlink search query path.
- Security
CVE-2026-40259 — SiYuan Knowledge Management Authorization
A high-severity authorization bypass in SiYuan versions 3.6.3 and below allows attackers with RoleReader publish-service tokens to call a privileged...
- Security
CVE-2026-40322: SiYuan XSS via Mermaid innerHTML Injection
SiYuan knowledge management versions 3.6.3 and below render Mermaid diagrams with loose security, allowing attacker-controlled javascript: URLs to execute...
- Security
CVE-2026-33669: SiYuan Unauthenticated Document Content
A critical unauthenticated information disclosure vulnerability in SiYuan, the personal knowledge management system, allows remote attackers to retrieve...
- Security
CVE-2026-33670: SiYuan readDir Path Traversal Notebook
A critical path traversal vulnerability in SiYuan's /api/file/readDir interface allows unauthenticated remote attackers to traverse notebook directories...