github.com/siyuan-note/siyuan/kernel vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-23645Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File UploadGHSA-4R66-7RCV-X46XHighgithub.com/siyuan-note/siyuan/kernel: SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBinCVE-2025-67488Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCECVE-2025-21609Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file deletion vulnerabilityCVE-2024-55657Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file read via /api/template/renderCVE-2024-55658Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesCVE-2024-55659Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file write in the host via /api/asset/uploadCVE-2024-55660Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has an SSTI via /api/template/renderSprig

Stop the waste.
Protect your environment with Kodem.