Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection
ID: 617f19be-e697-50bb-bd58-8e20deb87a8d
STIX ID: report--617f19be-e697-50bb-bd58-8e20deb87a8d
Feed Name: securityonline.info
Researchers disclosed CVE-2026-29183, a reflected XSS in SiYuan's /api/icon/getDynamicIcon endpoint that allows unauthenticated attackers to inject JavaScript via SVG payloads (type=8). The issue stems from an exposed endpoint, unsafe string formatting of user input into SVG, and incomplete sanitization that misses dangerous attributes (e.g., onerror/onload), enabling API abuse and exfiltration of private notes; recommendations include immediate updates, proper escaping of user input, and network isolation for self-hosted instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
