go

github.com/siyuan-note/siyuan/kernel

View on go registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/siyuan-note/siyuan/kernel is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.6
Go

GHSA-24r3-p3x6-cqvx

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

UNKNOWN
Go

CVE-2026-56395

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

MEDIUM 5.8
Go

GO-2026-6430

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

MEDIUM 5.8
Go

CVE-2026-72808

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

HIGH 8.6
Go

CVE-2026-72789

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

MEDIUM 5.8
Go

CVE-2026-72790

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

HIGH 8.6
Go

CVE-2026-68587

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

HIGH 8.6
Go

CVE-2026-72810

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

HIGH 7.7
Go

CVE-2026-59832

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

HIGH 8.6
Go

CVE-2026-72795

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

MEDIUM 5.8
Go

CVE-2026-72799

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

MEDIUM 5.8
Go

CVE-2026-72797

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers

HIGH 8.0
Go

CVE-2026-72809

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

MEDIUM 5.3
Go

CVE-2026-72802

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

HIGH 7.5
Go

CVE-2026-72801

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

HIGH 8.6
Go

CVE-2026-72804

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

MEDIUM 5.8
Go

CVE-2026-72796

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

MEDIUM 5.8
Go

CVE-2026-72800

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

MEDIUM 6.5
Go

CVE-2026-72812

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

MEDIUM 5.8
Go

CVE-2026-72806

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

HIGH 7.5
Go

CVE-2026-59834

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

HIGH 7.7
Go

CVE-2026-69086

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

HIGH 8.6
Go

CVE-2026-72798

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

CRITICAL 10.0
Go

CVE-2026-69084

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

HIGH 8.0
Go

CVE-2026-72807

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

HIGH 8.6
Go

CVE-2026-68586

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

UNKNOWN
Go

CVE-2026-65607

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

MEDIUM 6.5
Go

CVE-2026-65607

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

MEDIUM 5.8
Go

CVE-2026-72805

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

CRITICAL 10.0
Go

CVE-2026-69083

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

HIGH 8.6
Go

CVE-2026-72793

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

HIGH 8.6
Go

CVE-2026-72794

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

HIGH 8.6
Go

CVE-2026-68584

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

MEDIUM 5.8
Go

CVE-2026-72803

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

MEDIUM 5.8
Go

CVE-2026-72792

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

UNKNOWN
Go

CVE-2026-66394

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

HIGH 8.7
Go

CVE-2026-66394

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

CRITICAL 10.0
Go

CVE-2026-72811

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

MEDIUM 5.8
Go

CVE-2026-68585

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

UNKNOWN
Go

CVE-2026-72792

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72796

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

GHSA-57v5-wqx3-cgj4

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72793

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72804

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72789

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-59832

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72811

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72794

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72795

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72800

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72790

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72798

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72812

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72803

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72806

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72797

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72808

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72802

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72805

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72807

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-68586

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72801

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72810

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-69084

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-69083

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72799

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-68584

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-69086

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-68585

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-72809

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-68587

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

UNKNOWN
Go

CVE-2026-59834

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

HIGH 8.5
Go

CVE-2026-40318

SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

HIGH 8.6
Go

GHSA-g64v-qqpg-v37h

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

MEDIUM 5.8
Go

GHSA-mxjf-vfmv-qfm6

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

HIGH 8.6
Go

GHSA-xx34-6cjg-prh8

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

HIGH 8.6
Go

GHSA-cjwm-9h7g-pcr9

Duplicate Advisory: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

MEDIUM 5.8
Go

GHSA-f68g-4xv8-2g75

Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password

HIGH 8.6
Go

GHSA-2qqv-3jgq-vpm9

Duplicate Advisory: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

MEDIUM 5.8
Go

GHSA-rchc-g58m-88jm

Duplicate Advisory: getEncryptedNotebookStatus discloses names and live unlock state of all encrypted notebooks to anonymous readers

HIGH 8.6
Go

GHSA-mg8q-52j3-w5f8

Duplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

HIGH 8.6
Go

GHSA-hg4j-w33m-p7g4

Duplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

MEDIUM 5.8
Go

GHSA-cm9f-w4h4-7j85

Duplicate Advisory: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

MEDIUM 5.8
Go

GHSA-v3v5-7j3j-cc6f

Duplicate Advisory: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

MEDIUM 5.8
Go

GHSA-fxmw-rv85-5hwh

Duplicate Advisory: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

MEDIUM 5.3
Go

GHSA-72xp-24p9-7vpf

Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath

HIGH 7.5
Go

GHSA-hr3f-qfrh-h7w5

Duplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

HIGH 8.6
Go

GHSA-v598-7627-g9fx

Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

MEDIUM 5.8
Go

GHSA-89hf-xcx5-r9r6

Duplicate Advisory: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

MEDIUM 5.8
Go

GHSA-mhcc-g592-267j

Duplicate Advisory: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

MEDIUM 5.8
Go

GHSA-j26h-r8jx-887c

Duplicate Advisory: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

MEDIUM 5.8
Go

GHSA-h4w7-mgq4-wg6x

Duplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

HIGH 8.0
Go

GHSA-2jmx-q9jf-wp3w

Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

HIGH 8.6
Go

GHSA-q6g5-m978-c6v9

Duplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

HIGH 8.0
Go

GHSA-8wx9-j7j5-h9vp

Duplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port prox

CRITICAL 10.0
Go

GHSA-p8cp-78hp-wmq8

Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

MEDIUM 6.5
Go

GHSA-ww86-c2qf-w8fw

Duplicate Advisory: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

HIGH 8.6
Go

GHSA-85xq-27m5-59m9

Duplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

MEDIUM 5.8
Go

GHSA-3rfw-7fxw-6jxm

Duplicate Advisory: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

HIGH 7.7
Go

GHSA-x7jr-gvvr-p9w7

Duplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes