github.com/siyuan-note/siyuan/kernel
Go57 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/siyuan-note/siyuan/kernelpage 2 of 2
- CVE-2026-50551CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (…
- CVE-2026-54066HIGHCVSS 7.5EG 7.5✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path r…
- CVE-2026-54067CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs …
- CVE-2026-54068MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). Whe…
- CVE-2026-54069CRITICALCVSS 9.2EG 9.2✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension …
- CVE-2026-54070HIGHCVSS 7.1EG 7.1✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute saniti…
- CVE-2026-54158CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.0.0-20260628153353-2d5d72223df42026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value lik…
Check whether github.com/siyuan-note/siyuan/kernel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/siyuan-note/siyuan/kernel CVEs against the assets you own.
Start Free Scan →