CVE-2026-23645: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-23645 is a Stored Cross-Site Scripting (XSS) vulnerability in SiYuan Note, a self-hosted open source personal knowledge management application. The flaw exists because the application does not sanitize uploaded SVG files, allowing embedded JavaScript to execute in the context of an authenticated user's session when the file is viewed or exported. It affects all SiYuan versions prior to 3.5.4 (including 3.5.4-dev1), and was fixed in version 3.5.4-dev2. The vulnerability was disclosed on January 16, 2026, with a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting): the application permits authenticated users to upload .svg files without stripping embedded <script> tags or JavaScript event handlers from the SVG content. When the SVG asset is subsequently served from the server (e.g., via the assets endpoint) or opened through the export function, the browser renders and executes the embedded script in the user's authenticated session context. The fix, implemented in commit 11115da, adds server-side stripping of scripts from SVG assets by default, with a new opt-in setting (allowSVGScript) that users can enable at their own risk (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows arbitrary JavaScript to execute within the victim's authenticated SiYuan session, enabling an attacker to steal session tokens, access private knowledge base content, perform unauthorized actions on behalf of the user, or exfiltrate sensitive notes and data. Because SiYuan is self-hosted and may contain personal or organizational knowledge, the confidentiality and integrity of stored information are at risk. Availability is not directly impacted, but the scope of the XSS extends to the browser context of any user who views or exports the malicious SVG (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, demonstrating that an attacker can craft a malicious SVG file with embedded JavaScript and upload it to a SiYuan workspace; the script executes when any user opens or exports the file. The EPSS score is approximately 0.045% (low probability of widespread exploitation). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a target SiYuan instance: Locate a self-hosted SiYuan deployment running a version prior to 3.5.4 (e.g., via network scanning or knowledge of the target environment).
  2. Craft a malicious SVG file: Create a file named test.svg containing embedded JavaScript, for example:
<svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" viewBox="0 0 124 124" fill="none">
  <rect width="124" height="124" rx="24" fill="red"/>
  <script type="text/javascript">
    alert(window.origin); // Replace with payload: cookie theft, data exfiltration, etc.
  </script>
</svg>
  1. Upload the SVG: Log in to SiYuan (or use a compromised/shared account) and upload the malicious test.svg as an asset in a note (e.g., a Daily Note).
  2. Trigger execution: The script executes when any authenticated user either opens the SVG asset directly or right-clicks the asset and selects "Export," causing the browser to render and execute the embedded JavaScript in the user's session context.
  3. Achieve objective: The executed script can steal session cookies, exfiltrate note content, or perform actions on behalf of the victim user (GitHub Advisory).

Indicators of compromise

  • File System: Presence of .svg files in the SiYuan assets/ workspace directory containing <script> tags or JavaScript event handlers (e.g., onload, onerror).
  • Network: Unexpected outbound HTTP requests from the SiYuan server or client browser to external domains shortly after a user opens or exports an SVG asset; data exfiltration attempts (e.g., fetch, XMLHttpRequest, or img src beacon calls to attacker-controlled URLs).
  • Logs: SiYuan access logs showing requests to asset endpoints (e.g., /assets/*.svg) followed by unusual outbound connections from the client; browser console errors related to script execution within SVG context.
  • Application: Newly uploaded SVG files from untrusted or unknown sources appearing in workspace asset directories, especially those not created by known users (GitHub Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.5.4 or later, which strips scripts from SVG assets served by the server by default. The fix introduces a new editor setting — Settings → Editor → Allow execution of scripts inside SVG — that is disabled by default; users who require SVG script execution can opt in while acknowledging the XSS risk. Until upgrade is possible, avoid uploading or opening SVG files from untrusted sources within SiYuan workspaces (Fix Commit, GitHub Issue).

Community reactions

The vulnerability was reported by security researcher jaroslaw-wawiorko and acknowledged by the SiYuan maintainers, who issued a fix promptly in the 3.5.4-dev2 release. Coverage appeared on vulnerability aggregation platforms including Vulners, VulDB, and CVEFeed shortly after disclosure. A brief write-up was published at infinitsec.net covering the stored XSS via unrestricted SVG upload (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management