Robuta

https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34605/ SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon,... CVE-2026-34605 SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated): The SanitizeSVG function... https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/CVE-2026-32940/ SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for... CVE-2026-32940 SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183): Reflected XSS on an unauthenticated...