VDB
KO

GO-2026-5357

SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution in github.com/siyuan-note/siyuan/kernel

Details

SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution in github.com/siyuan-note/siyuan/kernel

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/siyuan-note/siyuan/kernel
Introduced in: 0 Fixed in: 0.0.0-20260329142331-918d1bd9f967
Fix go get github.com/siyuan-note/siyuan/kernel@v0.0.0-20260329142331-918d1bd9f967

References