Unathenticated Reflected XSS Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-29183

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-29183?

SiYuan, a personal knowledge management system, contains a reflected XSS vulnerability in its dynamic icon API prior to version 3.5.9. This vulnerability allows attackers to embed malicious, unescaped SVG content in the response of the API endpoint. Since the endpoint does not require authentication and serves content type image/svg+xml, an attacker can create a crafted URL that, when clicked by a logged-in user, executes JavaScript within the context of the SiYuan application. This enables potential attackers to perform harmful actions and potentially exfiltrate sensitive user data. Users are advised to upgrade to version 3.5.9 or later to mitigate this issue.

Affected Version(s)

siyuan < 3.5.9

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.