CVE-2026-31807: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-31807 is a reflected Cross-Site Scripting (XSS) vulnerability in SiYuan, a personal knowledge management system, caused by an incomplete SVG sanitizer that fails to block SVG animation elements (<animate>, <set>). It affects all SiYuan versions up to and including 3.5.9 and was disclosed on March 9, 2026, with a patch released in v3.5.10. This vulnerability is a bypass of the prior fix for CVE-2026-29183 (addressed in v3.5.9). It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 6.4 (Medium) (GitHub Advisory, GHSA).

Technical details

The root cause (CWE-79) lies in the SanitizeSVG() function in kernel/util/misc.go (lines 234–319), which blocks dangerous tags (<script>, <iframe>, <foreignobject>) and strips on* event handlers and javascript: from href attributes at parse time, but omits SVG animation elements (<animate>, <set>, <animateTransform>, <animateMotion>) from its blocklist. These elements can dynamically set attributes — such as href — to javascript: URIs at runtime, after static sanitization has already passed. The unauthenticated GET /api/icon/getDynamicIcon?type=8&content=... endpoint reflects user-supplied SVG content with Content-Type: image/svg+xml, causing browsers to render it as a standalone SVG document and execute the injected JavaScript. No authentication or special privileges are required; only user interaction (clicking a crafted link) is needed (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the SiYuan application's origin within the victim's browser. Because execution occurs in the application origin, the attacker gains full access to authenticated APIs, enabling session cookie theft, API token exfiltration, unauthorized note modification, and configuration theft. The vulnerability can be chained to perform actions on behalf of the victim, redirect to phishing sites, or exfiltrate sensitive knowledge base data (GitHub Advisory, GHSA).

Exploitability

A public proof-of-concept (PoC) with specific crafted HTTP GET request payloads is available in the GitHub Security Advisory, providing ready-to-use exploit steps against vulnerable SiYuan instances (GitHub Advisory). Nuclei templates for automated detection have also been added to the ProjectDiscovery nuclei-templates repository. The EPSS score is approximately 0.378% (60th percentile), indicating a moderate probability of exploitation in the near term. There is no confirmed evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GHSA).

Exploitation steps

  1. Reconnaissance: Identify internet-accessible SiYuan instances running version 3.5.9 or earlier. The /api/icon/getDynamicIcon endpoint requires no authentication and can be probed directly.
  2. Craft malicious payload (Vector 1 — <animate> href injection): Construct a URL with an SVG <animate> element that dynamically sets an <a> element's href to a javascript: URI:
    GET /api/icon/getDynamicIcon?type=8&content=</text><a><animate attributeName="href" values="javascript:alert(document.domain)" begin="0s" fill="freeze"/><text x="50%" y="80%" fill="red" style="font-size:60px">Click me</text></a><text>&color=blue
  3. Craft malicious payload (Vector 2 — <set> event handler injection): Alternatively, use a <set> element to dynamically inject an onmouseover event handler:
    GET /api/icon/getDynamicIcon?type=8&content=</text><set attributeName="onmouseover" to="alert(document.domain)"/><text>&color=blue
  4. Deliver the link: Send the crafted URL to a victim with an active SiYuan session via phishing email, chat message, or embedded link.
  5. Victim interaction: The victim navigates to the URL; the server responds with Content-Type: image/svg+xml, causing the browser to render the SVG as a standalone document.
  6. JavaScript execution: The <animate> element sets the <a> href to javascript:... at runtime (bypassing static sanitization); the victim clicks the link or triggers the event handler, executing the attacker's JavaScript in the SiYuan origin.
  7. Post-exploitation: The attacker's script exfiltrates session cookies, API tokens, or makes authenticated API calls to read/modify notes or steal configuration data (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or unexpected HTTP GET requests to /api/icon/getDynamicIcon?type=8&content= containing SVG animation tags (<animate, <set) or javascript: strings in the content parameter; outbound requests from the SiYuan server to unknown external hosts following such requests.
  • Logs: Web server access logs showing requests to /api/icon/getDynamicIcon with URL-encoded SVG payloads containing animate, set, attributeName, values, or javascript: substrings; repeated requests from the same IP with varying content parameter values (fuzzing behavior).
  • File System: No direct file system artifacts expected for reflected XSS; however, if post-exploitation API calls are made, look for unexpected note modifications, new API token generation events, or configuration file changes in the SiYuan data directory.
  • Process/Application: Unexpected authenticated API calls (e.g., note reads/writes, config exports) originating from sessions that were recently active on the /api/icon/getDynamicIcon endpoint (GitHub Advisory).

Mitigation and workarounds

Upgrade SiYuan to version v3.5.10 or later, which adds SVG animation elements (animate, set, animateTransform, animateMotion) to the sanitizer's blocklist and addresses the bypass (GitHub Advisory, GHSA). Until patching is possible, restrict or disable access to the /api/icon/getDynamicIcon endpoint via firewall rules or reverse proxy configuration. Additionally, implement a strict Content Security Policy (CSP) header to limit inline script execution and reduce the impact of any XSS exploitation. Users should be advised not to click unsolicited links pointing to their SiYuan instance.

Community reactions

The vulnerability was reported by security researcher 0xkakash1 and published via GitHub Security Advisory on March 9, 2026 (GitHub Advisory). The ProjectDiscovery team added Nuclei detection templates for this CVE, indicating community interest in automated scanning. A post on Bluesky by beikokucyber.bsky.social referenced the vulnerability, suggesting some social media awareness. No major vendor statements beyond the advisory or significant mainstream media coverage have been identified.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management