PT-2026-3492 · Siyuan · Siyuan

Jaroslaw-Wawiorko

·

Published

2026-01-19

·

Updated

2026-02-06

·

CVE-2026-23847

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.5.4
Description SiYuan is a personal knowledge management system susceptible to reflected cross-site scripting. The issue occurs in the /api/icon/getDynamicIcon API endpoint. The endpoint generates SVG images for text icons (type=8), and the content parameter is directly inserted into the SVG <text> tag without proper XML escaping. Because the response Content-Type is set to image/svg+xml, injecting unescaped tags can disrupt the XML structure and allow for JavaScript execution.
Recommendations Update to version 3.5.4 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23847
GHSA-W836-5GPM-7R93
GO-2026-4343
SUSE-SU-2026:0403-1

Affected Products

Siyuan