Unathenticated Reflected XSS Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-29183
9.3CRITICAL
What is CVE-2026-29183?
SiYuan, a personal knowledge management system, contains a reflected XSS vulnerability in its dynamic icon API prior to version 3.5.9. This vulnerability allows attackers to embed malicious, unescaped SVG content in the response of the API endpoint. Since the endpoint does not require authentication and serves content type image/svg+xml, an attacker can create a crafted URL that, when clicked by a logged-in user, executes JavaScript within the context of the SiYuan application. This enables potential attackers to perform harmful actions and potentially exfiltrate sensitive user data. Users are advised to upgrade to version 3.5.9 or later to mitigate this issue.
Affected Version(s)
siyuan < 3.5.9
