https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34605/
SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon,...
CVE-2026-34605 SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated): The SanitizeSVG function...
https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/CVE-2026-32940/
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for...
CVE-2026-32940 SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183): Reflected XSS on an unauthenticated...