SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate severity
GitHub Reviewed
Published
Mar 9, 2026
in
siyuan-note/siyuan
•
Updated Mar 10, 2026
Give feedback on Dependabot alerts