Github.com/siyuan-note/siyuan/kernel
36 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Github.com/siyuan-note/siyuan/kernel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Github.com/siyuan-note/siyuan/kernel CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 4 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 4 |
| 2026-02 | 2 |
| 2026-03 | 15 |
| 2026-04 | 4 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 4 |
Severity
How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High8
- Medium8
Latest CVEs
The 15 most recently published vulnerabilities affecting Github.com/siyuan-note/siyuan/kernel.
- GHSA-57v5-wqx3-cgj4SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews—
- GHSA-7j72-f6wg-cxw6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)—
- GHSA-gw25-m53r-qh88SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)—
- GHSA-99rq-75j6-5j9fSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass—
- GHSA-hjh7-r5w8-5872SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869)—
- GHSA-8q5w-mmxf-48jgSiYuan has incomplete fix for CVE-2026-33066: XSS—
- GHSA-vw86-c94w-v3x4SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`—
- GHSA-7m5h-w69j-qgggSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`—
- CVE-2026-32767SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API9.8
- CVE-2026-32751SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface9.0
- CVE-2026-32749SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write7.6
- CVE-2026-32747SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets6.8
- GHSA-fq2j-j8hc-8vw8SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service—
- GHSA-v3mg-9v85-fcm7SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS—
- GHSA-xp2m-98x8-rpj6SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure—
Product grouping is registry-driven, with AI assist and human review. How it works