Security: siyuan-note/siyuan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS via arbitrary-file assets served same-origin without Content-Disposition or X-Content-Type-Options, escalating to full kernel API accessGHSA-mjf3-jwmf-r6wf published
Aug 3, 2026 by 88250Critical -
Unescaped workspace path concatenated into a UAC-elevated command line allows local privilege escalation via the bundled elevator.exe helperGHSA-vmp7-pm7g-ghcc published
Aug 3, 2026 by 88250High -
Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypassGHSA-3cc2-h3v6-rqpq published
Aug 3, 2026 by 88250Low -
Unthrottled brute-force of `Conf.Api.Token` via header/query auth in `CheckAuth()`, allowing unlimited automated guessing of a weakened API admin tokenGHSA-m6w6-p7pc-fpg2 published
Aug 2, 2026 by 88250Critical -
PDF annotation fields are written to disk unparsed and rendered into five raw attributes, turning a shared PDF into Remote Code Execution on the desktop clientGHSA-fqpw-c3pj-w8g9 published
Aug 1, 2026 by 88250Critical -
Database menu labels are escaped in the attribute and left raw in the body of the same line, turning a field description into Remote Code Execution on the desktop clientGHSA-gcm3-qcq3-72rv published
Aug 1, 2026 by 88250Critical -
A database Template calculation becomes Remote Code Execution on the desktop client, because the sanitizer written for identical template output is never calledGHSA-rwh7-gm74-67h6 published
Aug 1, 2026 by 88250Critical -
Attribute-view column widths are stored without validation and interpolated into style attributes without escaping, allowing stored cross-site scripting in every table cellGHSA-rj55-w3xr-gj62 published
Aug 1, 2026 by 88250Critical