logo

Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection

ID: 617f19be-e697-50bb-bd58-8e20deb87a8d

STIX ID: report--617f19be-e697-50bb-bd58-8e20deb87a8d

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed CVE-2026-29183, a reflected XSS in SiYuan's /api/icon/getDynamicIcon endpoint that allows unauthenticated attackers to inject JavaScript via SVG payloads (type=8). The issue stems from an exposed endpoint, unsafe string formatting of user input into SVG, and incomplete sanitization that misses dangerous attributes (e.g., onerror/onload), enabling API abuse and exfiltration of private notes; recommendations include immediate updates, proper escaping of user input, and network isolation for self-hosted instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.