Technology · Go
github.com/siyuan-note/siyuan/kernel (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 158 vulnerabilities in github.com/siyuan-note/siyuan/kernel (Go): 0 in the last 7 days and 95 in the last 90 days, 18 of them critical and 0 exploited in the wild. The most recent, SiYuan database view metadata disclosure via API endpoint, was published on 10 September 2026.
- Last 7 days
- 0
- Last 90 days
- 95
- Critical, all time
- 18
- Exploited in the wild
- 0
About github.com/siyuan-note/siyuan/kernel (Go)
The core kernel component of the SiYuan note-taking application, providing data management and synchronization logic.
Latest github.com/siyuan-note/siyuan/kernel (Go) vulnerabilities
- SiYuan database view metadata disclosure via API endpointinfo
- CVE-2026-72789: SiYuan publish-access gate treats encrypted notebooks as public by defaulthighCVSS 8.6EPSS 0.5%
- CVE-2026-72790: SiYuan getNotebookInfo unauthorized disclosure in APImediumCVSS 5.8EPSS 0.3%
- SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttrilowCVSS 3.1
- SiYuan getAttributeViewFieldViews missing authorizationmediumCVSS 5.8
- CVE-2026-72792: SiYuan tag API information disclosure via password bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72793: SiYuan getConf information disclosure of session key and secretshighCVSS 8.6EPSS 0.4%
- CVE-2026-72795: SiYuan embedded block content leak via missing publish-access filteringhighCVSS 8.6EPSS 0.4%
- CVE-2026-72794: SiYuan session-cookie signing key disclosure in /api/system/getConfhighCVSS 8.6EPSS 0.4%
- CVE-2026-72796: SiYuan static routes access control bypassmediumCVSS 5.8EPSS 0.4%
- CVE-2026-72797: SiYuan getEncryptedNotebookStatus information disclosuremediumCVSS 5.8EPSS 0.3%
- CVE-2026-72798: SiYuan renderAttributeView missing authorization in related-database contenthighCVSS 8.6EPSS 0.4%
- CVE-2026-72799: SiYuan missing publish-access filter on path-resolution endpointsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72800: SiYuan missing authorization filters on API endpoints leaks database schema and block IDsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72801: SiYuan encrypted notebook key material and wrapped keys disclosurehighCVSS 7.5EPSS 0.4%
- CVE-2026-72802: SiYuan resolveAssetPath information disclosuremediumCVSS 5.3EPSS 0.3%
- CVE-2026-72803: SiYuan missing publish-access filter on getBlockAttrs and batchGetBlockAttrsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72804: SiYuan graph endpoints bypass publish password protectionhighCVSS 8.6EPSS 0.4%
- CVE-2026-72805: SiYuan missing authorization in block API endpointsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72806: SiYuan attribute-view database password bypass in publish modemediumCVSS 5.8EPSS 0.4%
- CVE-2026-72807: SiYuan second-order SQL injection via queryBlocks template functionhighCVSS 8EPSS 0.3%
- CVE-2026-72808: SiYuan missing authorization on getFileAnnotation endpointmediumCVSS 5.8EPSS 0.4%
- CVE-2026-72809: SiYuan kernel localhost-trust admin bypass on auth-gated endpointshighCVSS 8EPSS 0.3%
- CVE-2026-72810: SiYuan publish-boundary bypass via WebSocket broadcasthighCVSS 8.6EPSS 0.5%
- CVE-2026-72811: SiYuan backlink search SQL injection via unescaped metadata concatenationcriticalCVSS 10EPSS 0.4%
Most severe github.com/siyuan-note/siyuan/kernel (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69084: SiYuan arbitrary SQL execution via searchEmbedBlockcriticalCVSS 10EPSS 1.6%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-72811: SiYuan backlink search SQL injection via unescaped metadata concatenationcriticalCVSS 10EPSS 0.4%
- SiYuan SQL injection in backlink/mention searchcriticalCVSS 10
- SiYuan searchEmbedBlock SQL injectioncriticalCVSS 10
- CVE-2026-50551: SiYuan stored XSS to RCE in Attribute View asset cell renderercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-54067: SiYuan stored XSS to RCE via CSS snippet breakoutcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.5%
- CVE-2026-34449: SiYuan RCE via permissive CORS policy and snippet injectioncriticalCVSS 9.6EPSS 0.8%
- CVE-2026-56397: SiYuan RCE via unsanitized Bazaar marketplace metadata and READMEcriticalCVSS 9.6EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 10 | 1 | |
| 10 Aug 2026 | 46 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 30 | 3 | |
| 7 Sep 2026 | 5 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/siyuan-note/siyuan/kernel (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel, 26 September 2026.