Vivek | ThreatIntel[verified]@VivekIntelDisclosure
The advisory discloses a reflected XSS flaw in SiYuan that permits code execution via a dynamic SVG endpoint, detailing the exploit chain and providing upgrade and mitigation recommendations.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces a medium‑severity unauthenticated reflected XSS vulnerability (CVE‑2026‑29183) in all SiYuan Note versions and provides a link for further details.
Gray Hats@the_yellow_fallPatch
A critical 9.3 CVSS reflected XSS flaw in SiYuan’s dynamic icon API enables SVG injection to steal private notes; users should apply the pending update immediately.
PulsePatch.io@pulsepatchioDisclosure
The SiYuan application suffers from an unauthenticated reflected XSS vulnerability via SVG injection (CVE-2026-29183) that permits client‑side script execution.
PulsePatch.io@pulsepatchioDisclosure
The post announces an SVG sanitization bypass in SiYuan related to CVE-2026-29183, noting a potential content injection issue and urging users to watch for official patches.
CRAC Learning - Tech@cracbotDisclosure
The post identifies CVE-2026-29183 as a critical unauthenticated reflected XSS affecting SiYuan versions prior to 3.5.9, referencing the NVD entry for further details.
CVE@CVEnewDisclosure
The text announces a reflected XSS vulnerability in SiYuan’s dynamic icon API that can be triggered without authentication, but provides no PoC, exploit, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A brief alert announces CVE-2026-29183, an unauthenticated reflected XSS vulnerability in SiYuan Knowledge, with a link to a vulnerability details page but no further exploit or patch information.