Vulnerabilities
Last updated 40 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/* | Medium Risk 4.9 | 8 hours ago | 7 hours ago |
|
|
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist) | Medium Risk 6.0 | 8 hours ago | 7 hours ago |
|
|
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) | Medium Risk 5.7 | 3 days ago | 3 days ago |
|
|
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) | High Risk 8.2 | 3 days ago | 3 days ago |
|
|
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers | High Risk 7.5 | 3 days ago | 3 days ago |
|
|
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass | Low Risk 0.0 | 3 days ago | 3 days ago |
|
|
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering | Medium Risk 5.8 | 4 days ago | 4 days ago |
|
|
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block | Medium Risk 5.8 | 4 days ago | 4 days ago |
|
|
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check | Medium Risk 5.8 | 4 days ago | 4 days ago |
|
|
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem | Medium Risk 5.8 | 4 days ago | 4 days ago |
|
|
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking | Critical 10.0 | 4 days ago | 4 days ago |
|
|
SiYuan discloses an administrator's open documents and search terms to anonymous readers | Medium Risk 5.8 | 4 days ago | 4 days ago |
|
|
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS | Medium Risk 6.0 | 6 months ago | 21 days ago |
|
|
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews | Medium Risk 5.8 | 27 days ago | 25 days ago |
|
|
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked | High Risk 8.6 | 27 days ago | 25 days ago |
|
|
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo | Medium Risk 5.8 | 27 days ago | 25 days ago |
|
|
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db | High Risk 7.7 | 1 month ago | 25 days ago |
|
|
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy | High Risk 8.0 | 1 month ago | 25 days ago |
|
|
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking | High Risk 7.5 | 1 month ago | 25 days ago |
|
|
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath | Medium Risk 5.3 | 1 month ago | 25 days ago |
|
|
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) | Medium Risk 6.5 | 1 month ago | 25 days ago |
|
|
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure | High Risk 7.7 | 1 month ago | 25 days ago |
|
|
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content | High Risk 7.5 | 1 month ago | 25 days ago |
|
|
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write | Critical 10.0 | 1 month ago | 25 days ago |
|
|
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel | High Risk 8.0 | 1 month ago | 25 days ago |
|
|
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) | Medium Risk 6.5 | 1 month ago | 25 days ago |
|
|
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel | Unknown | 25 days ago | 25 days ago |
|
|
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB | Critical 10.0 | 1 month ago | 25 days ago |
|
|
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) | High Risk 8.6 | 1 month ago | 25 days ago |
|
|
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass | High Risk 8.7 | 1 month ago | 25 days ago |
|
|
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel | Unknown | 25 days ago | 25 days ago |
|
|
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered | Medium Risk 5.8 | 1 month ago | 25 days ago |
|
|
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle | Critical 10.0 | 1 month ago | 25 days ago |
Page 1