SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在跨站脚本漏洞,该漏洞源于提供任意文件资产时未设置Content-Disposition和X-Content-Type-Options标头,可能导致存储型跨站脚本攻击。经过身份验证的攻击者可上传HTML文件作为资产,并在工作区所有者打开资产链接时执行具有完整内核API访问权限的脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74799 | 9.3 CRITICAL | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure |
| CVE-2026-74798 | 8.7 HIGH | SiYuan kernel Path Traversal via database_clean MCP tool |
| CVE-2026-74801 | 8.2 HIGH | SiYuan before 3.7.4 Local Privilege Escalation via elevator.exe |
| CVE-2026-74802 | 8.2 HIGH | SiYuan 3.7.3 Cross-Site WebSocket Hijacking via network proxy |
| CVE-2026-74868 | 7.5 HIGH | SiYuan before 3.7.4 Brute-Force Authentication via Publish Service |
| CVE-2026-74867 | 4.2 MEDIUM | SiYuan before 3.7.4 Cross-Site Request Forgery via CheckAuth |
No comments yet