SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在跨站脚本漏洞,该漏洞源于文件上传验证流程未转义文件名,可能导致攻击者构造包含脚本负载的恶意文件名,当用户拖放或粘贴文件到编辑器时以完整操作系统命令权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74906 | 7.5 HIGH | SiYuan before v3.7.4 Incorrect Authorization via Publish Access |
| CVE-2026-74904 | 7.5 HIGH | SiYuan before v3.7.4 Missing Authorization via block API |
| CVE-2026-74905 | 7.1 HIGH | SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass |
| CVE-2026-74903 | 4.3 MEDIUM | SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM |
No comments yet