An open-source, privacy-first, self-hosted knowledge workspace where humans and AI agents work together 开源、隐私优先、自托管的知识工作空间,让人与智能体在此协作
github.com/siyuan-note/siyuan/kernel has critical vulnerabilities — do not use
Update to >= 0.0.0-20260628153353-2d5d72223df4 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | CVE-2026-44588 | SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585) | — |
| high | CVE-2024-55658 | SiYuan has an arbitrary file read and path traversal via /api/export/exportResources | — |
| critical | CVE-2026-45375 | SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution | — |
| critical | CVE-2026-30869 | SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage | 3.5.10 |
| critical | CVE-2026-44670 | SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE | 0.0.0-20260512140701-d7b77d945e0d |
| critical | CVE-2026-33669 | SiYuan has Arbitrary Document Reading within the Publishing Service | — |
| high | CVE-2026-33203 | SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass | 3.6.2 |
| medium | CVE-2026-33066 | SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering | 0.0.0-20260314111550-b382f50e1880 |
| medium | CVE-2026-32704 | SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB | 3.6.1 |
| medium | CVE-2024-55660 | SiYuan has an SSTI via /api/template/renderSprig | — |
| high | GO-2025-4219 | SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin | — |
| high | CVE-2026-32110 | SiYuan has a Full-Read SSRF via /api/network/forwardProxy | 3.6.0 |
| critical | CVE-2026-50551 | SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content | 0.0.0-20260628153353-2d5d72223df4 |
| medium | CVE-2026-31807 | SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS | 0.0.0-20260310025236-297bd526708f |
| critical | CVE-2026-54158 | SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() | 0.0.0-20260628153353-2d5d72223df4 |
| critical | CVE-2026-29183 | SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint | 0.0.0-20260304034809-d68bd5a79391 |
| critical | CVE-2026-34449 | SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | 3.6.2 |
| medium | CVE-2026-45147 | SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk | 0.0.0-20260512140701-d7b77d945e0d |
| high | CVE-2026-34605 | SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated) | 0.0.0-20260330031106-f09953afc57a |
| high | CVE-2026-40259 | SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView` | 0.0.0-20260407035653-2f416e5253f1 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/siyuan-note/siyuan/kernelLast updated · 2026-08-18T09:55:58Z