Loading...
Skip to main content
Go Modules

github.com/siyuan-note/siyuan/kernel Security Analysis

github.com/siyuan-note/siyuan/kernel has 22 known security vulnerabilities in Go Modules. Upgrade to version 3.6.40.0.0-20260407035653-2f416e5253f1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

22 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 3.6.40.0.0-20260407035653-2f416e5253f1

Upgrading to 3.6.40.0.0-20260407035653-2f416e5253f1 or later resolves all 22 known vulnerabilities in github.com/siyuan-note/siyuan/kernel. Run: go get github.com/siyuan-note/siyuan/kernel@v3.6.40.0.0-20260407035653-2f416e5253f1

Is github.com/siyuan-note/siyuan/kernel in your project?

Check if you're affected and upgrade to 3.6.40.0.0-20260407035653-2f416e5253f1 to stay secure.

22
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

22 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-50551
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CRITICAL
All versions0.0.0-20260628153353-2d5d72223df4
CVE-2026-54158
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CRITICAL
All versions0.0.0-20260628153353-2d5d72223df4
CVE-2026-54067
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CRITICAL
All versions0.0.0-20260628153353-2d5d72223df4
CVE-2026-33669
SiYuan has Arbitrary Document Reading within the Publishing Service
CRITICAL
All versionsNo fix available
CVE-2026-32938
SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service
CRITICAL
All versionsNo fix available
CVE-2026-33670
SiYuan has directory traversal within its publishing service
CRITICAL
All versionsNo fix available
CVE-2026-32767
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
CRITICAL
All versionsNo fix available
CVE-2026-44670
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
CRITICAL
All versions0.0.0-20260512140701-d7b77d945e0d
CVE-2026-34449
SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
CRITICAL
All versions3.6.2
CVE-2026-30869
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
CRITICAL
All versions3.5.10
CVE-2026-29183
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
CRITICAL
All versions0.0.0-20260304034809-d68bd5a79391
CVE-2026-44588
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
CRITICAL
All versionsNo fix available
CVE-2026-45375
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
CRITICAL
All versionsNo fix available
CVE-2026-25539
SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE
CRITICAL
All versionsNo fix available
CVE-2026-39846
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
CRITICAL
All versions0.0.0-20260407035653-2f416e5253f1
CVE-2026-34448
SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client
CRITICAL
All versions3.6.2
CVE-2026-40107
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
HIGH
All versions0.0.0-20260407035653-2f416e5253f1
CVE-2026-34585
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
HIGH
All versions0.0.0-20260329142331-918d1bd9f967
CVE-2026-40318
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
HIGH
All versions3.6.40.0.0-20260407035653-2f416e5253f1
CVE-2026-32110
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
HIGH
All versions3.6.0
CVE-2026-31809
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
MEDIUM
All versions0.0.0-20260310025236-297bd526708f
CVE-2026-31807
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
MEDIUM
All versions0.0.0-20260310025236-297bd526708f

About This Data

Vulnerability data for github.com/siyuan-note/siyuan/kernel is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of github.com/siyuan-note/siyuan/kernel.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed