PT-2026-3304 · Siyuan · Siyuan

Jaroslaw-Wawiorko

·

Published

2026-01-16

·

Updated

2026-02-06

·

CVE-2026-23645

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.5.4-dev2
Description SiYuan Note does not properly sanitize uploaded SVG files. This allows a user to upload a malicious SVG file, such as one obtained from an untrusted source, which can then execute arbitrary JavaScript code within the user's authenticated session when viewed. The application permits authenticated users to upload files, including .svg images, without removing potentially harmful JavaScript code embedded within them. The vulnerability is triggered when a user exports the malicious SVG file, causing the embedded JavaScript to execute in their browser.
Recommendations Update SiYuan to version 3.5.4-dev2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23645
GHSA-PCJQ-J3MQ-JV5J
GO-2026-4324
SUSE-SU-2026:0403-1

Affected Products

Siyuan