Skip to content

SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)

High severity GitHub Reviewed Published Mar 30, 2026 in siyuan-note/siyuan • Updated Apr 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts