siyuan-note siyuan

Published Atomicorp research notes for CVEs affecting siyuan-note siyuan where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2026-69083SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69084SiYuan - SQL Execution9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 344366 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69085SiYuan before v3.7.3 SQL Injection via searchDocs9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-66395SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol9.4 (v4.0)Critical333140 , 340095 , 341266
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotations9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadata9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-73043SiYuan before v3.7.4 Remote Code Execution via Template Calculation9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73044SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73050SiYuan before v3.7.4 Stored XSS via select option color9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73052SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73053SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageName9.4 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-66394SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass9.3 (v4.0)Critical300013 , 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-66396SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-74798SiYuan kernel Path Traversal via database_clean MCP tool9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-74902SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-87807siyuan before v3.8.2 SQL Injection via fullTextSearchBlock8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34605SiYuan Note - Cross-Site Scripting8.6 (v4.0)High300013
CVE-2026-84803SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist8.6 (v4.0)High333140 , 333141
CVE-2026-87811SiYuan before v3.8.2 Stored XSS via notebook template paths8.4 (v4.0)High333140 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-87814SiYuan before v3.8.2 Stored XSS via Asset Preview8.4 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avID8.3 (v4.0)High340007 , 344360 , 390709
CVE-2026-87812SiYuan before v3.8.2 Stored XSS via Bazaar iconURL7.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-59809SiYuan before v3.8.0 Secret Exfiltration via http_request URL6.9 (v4.0)Medium337109 , 347009 , 390722
CVE-2026-82233SiYuan before v3.8.1 Path Traversal via asset.upload6.9 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-31807SiYuan <= v3.5.9 - SVG Animate Element XSS6.4 (v4.0)Medium300013
CVE-2026-31809SiYuan <= v3.5.9 - Cross Site Scripting6.4 (v4.0)Medium300013
CVE-2026-29183SiYuan Note - Cross-Site Scripting6.1 (v3.1)Medium300013 , 340147 , 341266 , 347198
CVE-2026-82650SiYuan before v3.8.1 Path Traversal via /api/template/render5.9 (v4.0)Medium340007 , 344360 , 390709