Security Advisories for github.com/siyuan-note/siyuan/kernel in go
High
21 days ago
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
go
github.com/siyuan-note/siyuan/kernel
Moderate
21 days ago
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
go
github.com/siyuan-note/siyuan/kernel
Moderate
21 days ago
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
go
github.com/siyuan-note/siyuan/kernel
Moderate
25 days ago
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
go
github.com/siyuan-note/siyuan/kernel
High
25 days ago
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
go
github.com/siyuan-note/siyuan/kernel
High
25 days ago
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
go
github.com/siyuan-note/siyuan/kernel
High
25 days ago
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
go
github.com/siyuan-note/siyuan/kernel
Moderate
25 days ago
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
go
github.com/siyuan-note/siyuan/kernel
Moderate
25 days ago
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
go
github.com/siyuan-note/siyuan/kernel
High
25 days ago
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
go
github.com/siyuan-note/siyuan/kernel
Moderate
25 days ago
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
go
github.com/siyuan-note/siyuan/kernel
Critical
26 days ago
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
go
github.com/siyuan-note/siyuan/kernel
Critical
26 days ago
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
go
github.com/siyuan-note/siyuan/kernel
Critical
26 days ago
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
go
github.com/siyuan-note/siyuan/kernel
Moderate
26 days ago
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
go
github.com/siyuan-note/siyuan/kernel
High
26 days ago
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
go
github.com/siyuan-note/siyuan/kernel
High
27 days ago
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
go
github.com/siyuan-note/siyuan/kernel
High
27 days ago
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
go
github.com/siyuan-note/siyuan/kernel
Critical
3 months ago
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
go
github.com/siyuan-note/siyuan/kernel
Critical
3 months ago
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
go
github.com/siyuan-note/siyuan/kernel
High
3 months ago
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
go
github.com/siyuan-note/siyuan/kernel
Critical
3 months ago
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
go
github.com/siyuan-note/siyuan/kernel
Moderate
3 months ago
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
go
github.com/siyuan-note/siyuan/kernel
Critical
3 months ago
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
go
github.com/siyuan-note/siyuan/kernel
High
3 months ago
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
go
github.com/siyuan-note/siyuan/kernel
Critical
5 months ago
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
go
github.com/siyuan-note/siyuan/kernel
High
5 months ago
SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
go
github.com/siyuan-note/siyuan/kernel
Moderate
5 months ago
SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode
go
github.com/siyuan-note/siyuan/kernel
Moderate
5 months ago
SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
go
github.com/siyuan-note/siyuan/kernel
Critical
5 months ago
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
go
github.com/siyuan-note/siyuan/kernel
Critical
5 months ago
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
go
github.com/siyuan-note/siyuan/kernel
High
5 months ago
SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869)
go
github.com/siyuan-note/siyuan/kernel
Moderate
6 months ago
SiYuan has incomplete fix for CVE-2026-33066: XSS
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
go
github.com/siyuan-note/siyuan/kernel
Critical
6 months ago
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmark
go
github.com/siyuan-note/siyuan/kernel
Critical
6 months ago
SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
go
github.com/siyuan-note/siyuan/kernel
Critical
6 months ago
SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client
go
github.com/siyuan-note/siyuan/kernel
Critical
6 months ago
SiYuan has directory traversal within its publishing service
go
github.com/siyuan-note/siyuan/kernel
Critical
6 months ago
SiYuan has Arbitrary Document Reading within the Publishing Service
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal
go
github.com/siyuan-note/siyuan/kernel
High
6 months ago
SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
go
github.com/siyuan-note/siyuan/kernel
Moderate
6 months ago
SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home (GHSA-h5vh-m7fg-w5h6 Bypass)
go
github.com/siyuan-note/siyuan/kernel
Moderate
6 months ago
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
go
github.com/siyuan-note/siyuan/kernel
Moderate
6 months ago
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
go
github.com/siyuan-note/siyuan/kernel
Critical
7 months ago
SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service
go
github.com/siyuan-note/siyuan/kernel
Critical
7 months ago
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
go
github.com/siyuan-note/siyuan/kernel
High
7 months ago
SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file write
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secrets
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
go
github.com/siyuan-note/siyuan/kernel
High
7 months ago
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
go
github.com/siyuan-note/siyuan/kernel
High
7 months ago
SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildren
go
github.com/siyuan-note/siyuan/kernel
Critical
7 months ago
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
go
github.com/siyuan-note/siyuan/kernel
Critical
7 months ago
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
go
github.com/siyuan-note/siyuan/kernel
Moderate
7 months ago
SiYuan's direct SQL Query API accessible to Reader-level users enables unauthorized database access
go
github.com/siyuan-note/siyuan/kernel
Critical
8 months ago
SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE
go
github.com/siyuan-note/siyuan/kernel
High
8 months ago
SiYuan File Read API Case Sensitivity Bypass can Lead to Path Traversal
go
github.com/siyuan-note/siyuan/kernel
High
8 months ago
SiYuan vulnerable to Arbitrary file Read / SSRF
go
github.com/siyuan-note/siyuan/kernel
High
8 months ago
SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality
go
github.com/siyuan-note/siyuan/kernel
Low
8 months ago
SiYuan has a Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon
go
github.com/siyuan-note/siyuan/kernel
Moderate
9 months ago
SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File Upload
go
github.com/siyuan-note/siyuan/kernel
High
10 months ago
SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
go
github.com/siyuan-note/siyuan/kernel
High
10 months ago
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
go
github.com/siyuan-note/siyuan/kernel
High
over 1 year ago
SiYuan has an arbitrary file deletion vulnerability
go
github.com/siyuan-note/siyuan/kernel
High
almost 2 years ago
SiYuan has an arbitrary file read via /api/template/render
go
github.com/siyuan-note/siyuan/kernel
High
almost 2 years ago
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
go
github.com/siyuan-note/siyuan/kernel
High
almost 2 years ago
SiYuan has an arbitrary file write in the host via /api/asset/upload
go
github.com/siyuan-note/siyuan/kernel
Moderate
almost 2 years ago
SiYuan has an SSTI via /api/template/renderSprig
go
github.com/siyuan-note/siyuan/kernel