/Vulnerability Library

SiYuan Note - Cross-Site Scripting

CVE-2026-34605
Verified

Description

SiYuan Note through version 3.6.1 is vulnerable to unauthenticated reflected Cross-Site Scripting (XSS) in the `/api/icon/getDynamicIcon` endpoint due to improper filtering of SVG elements with a namespace prefix (such as `<x:script>`). By using a namespaced script element, attackers can bypass the `SanitizeSVG` function and execute arbitrary JavaScript in the victim’s browser upon visiting a crafted link.

Severity

Medium

CVSS Score

6.1

Exploit Probability

1%

Affected Product

siyuan

Published Date

March 31, 2026

Template Author

ritikchaddha

CVE-2026-34605.yaml
6.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2026-34605
CWE ID:
cwe-79

References

https://github.com/siyuan-note/siyuan/security/advisories/GHSA-73g7-86qr-jrg3https://nvd.nist.gov/vuln/detail/CVE-2026-34605

Remediation Steps

Upgrade to SiYuan Note version 3.6.2 or later, where the namespace prefix is stripped prior to sanitization, blocking this form of XSS.