PT-2026-3304 · Siyuan · Siyuan
Jaroslaw-Wawiorko
·
Published
2026-01-16
·
Updated
2026-02-06
·
CVE-2026-23645
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.5.4-dev2
Description
SiYuan Note does not properly sanitize uploaded SVG files. This allows a user to upload a malicious SVG file, such as one obtained from an untrusted source, which can then execute arbitrary JavaScript code within the user's authenticated session when viewed. The application permits authenticated users to upload files, including .svg images, without removing potentially harmful JavaScript code embedded within them. The vulnerability is triggered when a user exports the malicious SVG file, causing the embedded JavaScript to execute in their browser.
Recommendations
Update SiYuan to version 3.5.4-dev2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan