思源笔记(SiYuan)v3.8.3 存在安全漏洞。该版本在生成侧栏按钮(gutter-button)标记时,未对 data-subtype 属性进行 HTML 转义处理。相关代码位于 app/src/protyle/gutter/button.ts,并通过 app/src/protyle/gutter/index.ts 中的 innerHTML 赋值操作生成标记。 当用户粘贴以纯文本 Markdown 格式传入的、包含 Kramdown 内联属性列表(IAL)的内容时,共享的 Lute 渲染器会从 text/pl
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100646 | 8.1 HIGH | SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header |
| CVE-2026-100645 | 8.0 HIGH | SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban |
| CVE-2026-100643 | 8.0 HIGH | SiYuan before v3.8.4 Stored XSS via Attribute View textarea |
| CVE-2026-100641 | 8.0 HIGH | SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content |
| CVE-2026-100642 | 7.6 HIGH | SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth |
| CVE-2026-100637 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID |
| CVE-2026-100638 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via setNotebookIcon |
| CVE-2026-100636 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder |
| CVE-2026-100644 | 7.5 HIGH | SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath |
| CVE-2026-100633 | 6.5 MEDIUM | SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations |
| CVE-2026-100635 | 5.9 MEDIUM | SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie |
| CVE-2026-100634 | 4.7 MEDIUM | SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows |
| CVE-2026-100640 | 4.7 MEDIUM | SiYuan before v3.8.4 Clipboard Data Disclosure via IPC |
No comments yet