
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23645 is a Stored Cross-Site Scripting (XSS) vulnerability in SiYuan Note, a self-hosted open source personal knowledge management application. The flaw exists because the application does not sanitize uploaded SVG files, allowing embedded JavaScript to execute in the context of an authenticated user's session when the file is viewed or exported. It affects all SiYuan versions prior to 3.5.4 (including 3.5.4-dev1), and was fixed in version 3.5.4-dev2. The vulnerability was disclosed on January 16, 2026, with a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting): the application permits authenticated users to upload .svg files without stripping embedded <script> tags or JavaScript event handlers from the SVG content. When the SVG asset is subsequently served from the server (e.g., via the assets endpoint) or opened through the export function, the browser renders and executes the embedded script in the user's authenticated session context. The fix, implemented in commit 11115da, adds server-side stripping of scripts from SVG assets by default, with a new opt-in setting (allowSVGScript) that users can enable at their own risk (GitHub Advisory, Fix Commit).
Successful exploitation allows arbitrary JavaScript to execute within the victim's authenticated SiYuan session, enabling an attacker to steal session tokens, access private knowledge base content, perform unauthorized actions on behalf of the user, or exfiltrate sensitive notes and data. Because SiYuan is self-hosted and may contain personal or organizational knowledge, the confidentiality and integrity of stored information are at risk. Availability is not directly impacted, but the scope of the XSS extends to the browser context of any user who views or exports the malicious SVG (GitHub Advisory).
A proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, demonstrating that an attacker can craft a malicious SVG file with embedded JavaScript and upload it to a SiYuan workspace; the script executes when any user opens or exports the file. The EPSS score is approximately 0.045% (low probability of widespread exploitation). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
test.svg containing embedded JavaScript, for example:<svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" viewBox="0 0 124 124" fill="none">
<rect width="124" height="124" rx="24" fill="red"/>
<script type="text/javascript">
alert(window.origin); // Replace with payload: cookie theft, data exfiltration, etc.
</script>
</svg>test.svg as an asset in a note (e.g., a Daily Note)..svg files in the SiYuan assets/ workspace directory containing <script> tags or JavaScript event handlers (e.g., onload, onerror).fetch, XMLHttpRequest, or img src beacon calls to attacker-controlled URLs)./assets/*.svg) followed by unusual outbound connections from the client; browser console errors related to script execution within SVG context.Upgrade SiYuan to version 3.5.4 or later, which strips scripts from SVG assets served by the server by default. The fix introduces a new editor setting — Settings → Editor → Allow execution of scripts inside SVG — that is disabled by default; users who require SVG script execution can opt in while acknowledging the XSS risk. Until upgrade is possible, avoid uploading or opening SVG files from untrusted sources within SiYuan workspaces (Fix Commit, GitHub Issue).
The vulnerability was reported by security researcher jaroslaw-wawiorko and acknowledged by the SiYuan maintainers, who issued a fix promptly in the 3.5.4-dev2 release. Coverage appeared on vulnerability aggregation platforms including Vulners, VulDB, and CVEFeed shortly after disclosure. A brief write-up was published at infinitsec.net covering the stored XSS via unrestricted SVG upload (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."