Tag
#SiYuan
CVE-2026-68587: SiYuan Information Disclosure Vulnerability
A critical vulnerability (CVE-2026-68587) has been discovered in SiYuan versions before v3.7.3, allowing anonymous readers or users with publish RoleReader tokens to access restricted content. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. Affected users should update to version 3.7.3 or later.
Critical Vulnerability in SiYuan Note-Taking Application Allows Unauthorized Content Disclosure (CVE-2026-68586)
A critical vulnerability (CVE-2026-68586) with a CVSS score of 8.6 affects the SiYuan note-taking application before version 3.7.3. The vulnerability allows a publish-mode reader, including anonymous readers, to retrieve rendered DOM content of publish-forbidden documents and determine if a document references a given block. Immediate patching to version 3.7.3 or later is recommended.
Critical XSS Vulnerability in SiYuan's Bazaar Marketplace (CVE-2026-56397)
A critical vulnerability (CVE-2026-56397) with a CVSS score of 9.6 was discovered in SiYuan's Bazaar marketplace. The vulnerability allows malicious package authors to inject arbitrary HTML and JavaScript into package metadata and README content, leading to remote code execution on users browsing the Bazaar. This affects SiYuan versions before v3.6.1. Immediate patching to v3.6.1 or later is recommended.