CRITICAL9.3Go
GHSA-4mx9-3c2h-hwhg· CVE-2026-32940, GO-2026-4721SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
Modified: 4/2/2026
package
pkg:go/github.com/siyuan-note/siyuan
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
Modified: 4/2/2026
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Modified: 3/30/2026
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes in github.com/siyuan-note/siyuan
Modified: 3/26/2026
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183) in github.com/siyuan-note/siyuan
Modified: 3/26/2026