Skip to content

SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS

Moderate severity GitHub Reviewed Published Mar 9, 2026 in siyuan-note/siyuan • Updated Mar 10, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts