github.com/siyuan-note/siyuan/kernel Security Analysis
github.com/siyuan-note/siyuan/kernel has 22 known security vulnerabilities in Go Modules. Upgrade to version 3.6.40.0.0-20260407035653-2f416e5253f1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 3.6.40.0.0-20260407035653-2f416e5253f1
Upgrading to 3.6.40.0.0-20260407035653-2f416e5253f1 or later resolves all 22 known vulnerabilities in github.com/siyuan-note/siyuan/kernel. Run: go get github.com/siyuan-note/siyuan/kernel@v3.6.40.0.0-20260407035653-2f416e5253f1
Is github.com/siyuan-note/siyuan/kernel in your project?
Check if you're affected and upgrade to 3.6.40.0.0-20260407035653-2f416e5253f1 to stay secure.
Vulnerabilities
22 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-50551 SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content | CRITICAL | All versions | 0.0.0-20260628153353-2d5d72223df4 |
| CVE-2026-54158 SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() | CRITICAL | All versions | 0.0.0-20260628153353-2d5d72223df4 |
| CVE-2026-54067 SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() | CRITICAL | All versions | 0.0.0-20260628153353-2d5d72223df4 |
| CVE-2026-33669 SiYuan has Arbitrary Document Reading within the Publishing Service | CRITICAL | All versions | No fix available |
| CVE-2026-32938 SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service | CRITICAL | All versions | No fix available |
| CVE-2026-33670 SiYuan has directory traversal within its publishing service | CRITICAL | All versions | No fix available |
| CVE-2026-32767 SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API | CRITICAL | All versions | No fix available |
| CVE-2026-44670 SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE | CRITICAL | All versions | 0.0.0-20260512140701-d7b77d945e0d |
| CVE-2026-34449 SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | CRITICAL | All versions | 3.6.2 |
| CVE-2026-30869 SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage | CRITICAL | All versions | 3.5.10 |
| CVE-2026-29183 SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint | CRITICAL | All versions | 0.0.0-20260304034809-d68bd5a79391 |
| CVE-2026-44588 SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585) | CRITICAL | All versions | No fix available |
| CVE-2026-45375 SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution | CRITICAL | All versions | No fix available |
| CVE-2026-25539 SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE | CRITICAL | All versions | No fix available |
| CVE-2026-39846 SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions | CRITICAL | All versions | 0.0.0-20260407035653-2f416e5253f1 |
| CVE-2026-34448 SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client | CRITICAL | All versions | 3.6.2 |
| CVE-2026-40107 SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering | HIGH | All versions | 0.0.0-20260407035653-2f416e5253f1 |
| CVE-2026-34585 SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution | HIGH | All versions | 0.0.0-20260329142331-918d1bd9f967 |
| CVE-2026-40318 SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView` | HIGH | All versions | 3.6.40.0.0-20260407035653-2f416e5253f1 |
| CVE-2026-32110 SiYuan has a Full-Read SSRF via /api/network/forwardProxy | HIGH | All versions | 3.6.0 |
| CVE-2026-31809 SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS | MEDIUM | All versions | 0.0.0-20260310025236-297bd526708f |
| CVE-2026-31807 SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS | MEDIUM | All versions | 0.0.0-20260310025236-297bd526708f |
About This Data
Vulnerability data for github.com/siyuan-note/siyuan/kernel is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Go Modules Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of github.com/siyuan-note/siyuan/kernel.