
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29183 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability via SVG injection in SiYuan, a personal knowledge management system developed by b3log. The flaw exists in the dynamic icon API endpoint GET /api/icon/getDynamicIcon when the type=8 parameter is used, where attacker-controlled content is embedded into SVG output without proper escaping. All versions prior to 3.5.9 are affected. The vulnerability was published on March 4, 2026, and patched in version 3.5.9. The GitHub Advisory Database rates this as Critical with a CVSS v3.1 score of 9.3, while NVD records a score of 6.1 (Medium) (GitHub Advisory, SiYuan Advisory).
The root cause is improper neutralization of user input during web page generation (CWE-79). The /api/icon/getDynamicIcon endpoint is registered in SiYuan's unauthenticated router section (kernel/api/router.go), meaning no authentication middleware protects it. In the generateTypeEightSVG function (kernel/api/icon.go), user-supplied content is injected directly into SVG markup via %s string formatting without XML/HTML escaping. The existing sanitizer (RemoveScriptsInSVG in kernel/util/misc.go) only strips <script> nodes but fails to remove dangerous event handler attributes such as onerror and onload, allowing payloads like </text><image href=x onerror=alert(document.domain)></image><text> to survive and execute. Because the endpoint returns image/svg+xml, browsers render the SVG in the SiYuan web origin, enabling full JavaScript execution (GitHub Advisory, SiYuan Advisory).
Successful exploitation allows arbitrary JavaScript execution within the SiYuan web origin. If a logged-in user opens a crafted malicious URL, the attacker's script can abuse same-origin API access to perform authenticated actions on behalf of the victim, including exfiltrating sensitive data such as private notes, configuration files, and API responses. Depending on the victim's privileges and deployment mode (e.g., server-mode SiYuan exposed to a network), chained exploitation could lead to broader server-side impact. Confidentiality and integrity are both rated High in the vendor's CVSS assessment, with no availability impact (GitHub Advisory, SecurityOnline).
A public proof-of-concept (PoC) is available in the GitHub Security Advisory, demonstrating exploitation via a crafted URL requiring only that a logged-in user open the link — no attacker authentication is needed (SiYuan Advisory). Nuclei detection templates for this CVE have been added to the ProjectDiscovery nuclei-templates repository, further lowering the barrier to automated scanning (Nuclei Templates). The EPSS score is approximately 0.033–0.462% depending on the source, indicating a relatively low but non-negligible probability of exploitation in the wild within 30 days. There is no current evidence of in-the-wild exploitation or CISA KEV catalog listing, and no specific threat actor attribution has been reported (GitHub Advisory).
content parameter. Example:http://<target>:6806/api/icon/getDynamicIcon?type=8&content=%3C%2Ftext%3E%3Cimage%20href%3Dx%20onerror%3Dalert(document.domain)%3E%3C%2Fimage%3E%3Ctext%3Eonerror event handler executes the attacker's JavaScript.alert() payload with JavaScript that calls SiYuan's privileged same-origin APIs (e.g., to list notebooks, read notes, or export data), then exfiltrates the results to an attacker-controlled server via fetch() or XMLHttpRequest.
(GitHub Advisory, SiYuan Advisory)/api/icon/getDynamicIcon with type=8 and URL-encoded HTML/SVG content in the content parameter (e.g., %3C%2Ftext%3E, onerror, onload); outbound HTTP requests from the SiYuan server or victim browser to unknown external hosts shortly after such requests./api/icon/getDynamicIcon?type=8&content=<encoded_payload> from external or unexpected IP addresses; repeated access to this endpoint with varying content values may indicate scanning activity./api/notebook/lsNotebooks, /api/export/exportMd) originating from a browser session immediately following access to the dynamic icon endpoint.Upgrade SiYuan to version 3.5.9 or later, which patches the vulnerability by properly escaping user-supplied content before embedding it into SVG output (SiYuan Advisory). For deployments that cannot be immediately patched, restrict network access to the SiYuan instance (e.g., bind to localhost only, use a firewall to block external access to port 6806), and educate users to avoid clicking on unsolicited links pointing to SiYuan endpoints. Implementing a reverse proxy with a Web Application Firewall (WAF) that blocks requests containing SVG event handler patterns in query parameters can provide additional defense-in-depth (GitHub Advisory).
SecurityOnline covered the vulnerability with a headline emphasizing the critical CVSS score and the risk of private note theft via SVG injection (SecurityOnline). The Hacker Wire also published coverage of the flaw (The Hacker Wire). Community discussion was observed on Mastodon and Bluesky, with security researchers sharing the advisory shortly after publication. The vulnerability was reported by researcher maru1009 and acknowledged by the SiYuan maintainers, who released a patch promptly (SiYuan Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."