—
GO-2026-4721
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183) in github.com/siyuan-note/siyuan
Details
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183) in github.com/siyuan-note/siyuan
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/siyuan-note/siyuan
Introduced in:
0No fixed version published yet for github.com/siyuan-note/siyuan (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4mx9-3c2h-hwhg[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32940[ADVISORY]
- https://github.com/siyuan-note/siyuan/commit/d01d561875d4f744e9f6232f1d4831e3642b8696[FIX]
- https://github.com/advisories/GHSA-6865-qjcf-286f[WEB]
- https://github.com/siyuan-note/siyuan/releases/tag/v3.6.1[WEB]