Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pcjq-j3mq-jv5j | SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File Upload |
Fri, 30 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
B3log
B3log siyuan |
|
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* cpe:2.3:a:b3log:siyuan:3.5.4:dev1:*:*:*:*:*:* |
|
| Vendors & Products |
B3log
B3log siyuan |
|
| Metrics |
cvssV3_1
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Sat, 17 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views a malicious SVG file (e.g., imported from an untrusted source), arbitrary JavaScript code is executed in the context of their authenticated session. This vulnerability is fixed in 3.5.4-dev2. | |
| Title | SiYuan Vulnerable to Stored Cross-Site Scripting (XSS) via Unrestricted SVG File Upload | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-16T21:37:58.336Z
Reserved: 2026-01-14T16:08:37.484Z
Link: CVE-2026-23645
Updated: 2026-01-16T21:37:54.255Z
Status : Analyzed
Published: 2026-01-16T20:15:49.880
Modified: 2026-01-30T19:32:11.660
Link: CVE-2026-23645
No data.
OpenCVE Enrichment
Updated: 2026-04-18T16:15:04Z
Github GHSA