CVE-2026-29183Disclosure(b3log / siyuan)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when type=8, attacker-controlled content is embedded into SVG output without escaping. Because the endpoint is unauthenticated and returns image/svg+xml, a crafted URL can inject executable SVG/HTML event handlers (for example onerror) and run JavaScript in the SiYuan web origin. This can be chained to perform authenticated API actions and exfiltrate sensitive data when a logged-in user opens the malicious link. This issue has been patched in version 3.5.9.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 9 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 6 mentions (2026-03-06); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline12 mentions / 7d
02356Mentions · 2026-03-06: 6Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 1Mentions · 2026-03-23: 1Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-06: 5Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-01: 103-0603-0703-0903-1103-1803-2304-01
Signal classification3 categories
Disclosure
975.0%
Patch
216.7%
General
18.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-066
Disclosure4General1Patch1
2026-03-071
Disclosure1
2026-03-091
Patch1
2026-03-111
Disclosure1
2026-03-181
Disclosure1
2026-03-231
Disclosure1
2026-04-011
Disclosure1
Full discourse12 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-29183 - medium 🚨 SiYuan Note - Cross-Site Scripting > Unauthenticated reflected cross-site scripting (XSS) vulnerability in all versions of... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-29183 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a medium‑severity unauthenticated reflected XSS vulnerability (CVE‑2026‑29183) in all SiYuan Note versions and provides a link for further details.

    00012198
    905 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.3 CVSS reflected XSS flaw (CVE-2026-29183) in SiYuan's dynamic icon API lets attackers steal private notes via SVG injection. Update now. #SiYuan #CVE #CyberSecurity #XSS #InfoSec #Vulnerability #PatchAlert #AppSec #SVGInjection #ThreatIntel https://securityonline.info/critical-9-3-cvss-flaw-in-siyuan-lets-hackers-steal-private-notes-via-svg-injection/ https://t.co/Jdpzt9ilUE

    Post summary

    A critical 9.3 CVSS reflected XSS flaw in SiYuan’s dynamic icon API enables SVG injection to steal private notes; users should apply the pending update immediately.

    11010429
    10.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `SiYuan` application is susceptible to unauthenticated reflected XSS via SVG injection (CVE-2026-29183). This flaw allows client-side script execution. Review exposure. #XSS #infosec #WebSecurity https://www.pulsepatch.io/posts/cve-2026-29183-siyuan-svg-xss

    Post summary

    The SiYuan application suffers from an unauthenticated reflected XSS vulnerability via SVG injection (CVE-2026-29183) that permits client‑side script execution.

    0000048
    2 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An SVG sanitization bypass (GHSA-4mx9-3c2h-hwhg) affects `SiYuan` due to an incomplete fix for CVE-2026-29183. This could lead to content injection. Monitor for official patches. #SiYuan #SVG #SecurityBypass https://www.pulsepatch.io/posts/siyuan-svg-sanitize-bypass-vulnerability

    Post summary

    The post announces an SVG sanitization bypass in SiYuan related to CVE-2026-29183, noting a potential content injection issue and urging users to watch for official patches.

    0000026
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-29183 (CVSS:9.3, CRITICAL) is Analyzed. SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability..https://nvd.nist.gov/vuln/detail/CVE-2026-29183 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post identifies CVE-2026-29183 as a critical unauthenticated reflected XSS affecting SiYuan versions prior to 3.5.9, referencing the NVD entry for further details.

    0000052
    172 followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Disclosure

    CVE-2026-29183 — Reflected XSS in SiYuan enables code execution via SVG endpoint A critical vulnerability has been identified in SiYuan (≤ v3.5.8) involving the unauthenticated endpoint: GET /api/icon/getDynamicIcon The API generates SVG icons dynamically but fails to properly sanitize user-controlled input when type=8 is used. Because the response is returned with an image/svg+xml content type, modern browsers interpret the payload as an active document. Attack vector An attacker can craft a malicious URL embedding SVG/HTML event handlers (e.g., onerror) that execute arbitrary JavaScript in the SiYuan application origin when the link is opened. Observed exploitation chain • Initial access: crafted URL sent to a target user • Execution: browser renders malicious SVG payload • Context: JavaScript executes under SiYuan origin • Post-exploitation: authenticated API requests and workspace access Potential impact • Full account takeover within the SiYuan instance • Exfiltration of notes, documents, and stored workspace data • Potential pivot into connected environments via stolen session context Remediation Upgrade immediately to SiYuan v3.5.9 or later. If patching is delayed: • Avoid opening untrusted links referencing the SiYuan instance • Apply WAF filtering for malicious SVG/HTML event handler patterns targeting the endpoint Source: https://yazoul.net/advisory/cve/cve-2026-29183 #CyberSecurity #ThreatIntel #CVE #XSS

    Post summary

    The advisory discloses a reflected XSS flaw in SiYuan that permits code execution via a dynamic SVG endpoint, detailing the exploit chain and providing upgrade and mitigation recommendations.

    0000078
    188 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29183 SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET … https://www.cve.org/CVERecord?id=CVE-2026-29183

    Post summary

    The text announces a reflected XSS vulnerability in SiYuan’s dynamic icon API that can be triggered without authentication, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000120
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29183 Unauthenticated Reflected XSS Vulnerability in SiYuan Knowledge M... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29183 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief alert announces CVE-2026-29183, an unauthenticated reflected XSS vulnerability in SiYuan Knowledge, with a link to a vulnerability details page but no further exploit or patch information.

    0000044
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29183: CRITICAL] Unauthenticated reflected XSS vulnerability fixed in SiYuan 3.5.9. Attackers could inject JavaScript via crafted URLs to exfiltrate data from logged-in users.#cve,CVE-2026-29183,#cybersecurity https://cvefind.com/CVE-2026-29183

    Post summary

    The post highlights a critical unauthenticated reflected XSS vulnerability in SiYuan, noting that it was fixed in version 3.5.9, but provides no evidence of active exploitation or PoC.

    0000095
    597 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29183 Intel Report: https://ift.tt/inPMy47

    Post summary

    The tweet merely cites CVE-2026-29183 and links to an Intel report without providing PoC, exploitation details, or mitigation information.

    0000036
    343 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29183 - SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution Intel Report: https://ift.tt/jOqaxfU

    Post summary

    The alert reports CVE-2026-29183 as an unauthenticated reflected SVG XSS in SiYuan’s `/api/icon/getDynamicIcon` endpoint that allows arbitrary JavaScript execution, without indicating exploitation or remediation details.

    0000035
    343 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29183 - Critical SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicI... https://www.thehackerwire.com/vulnerability/CVE-2026-29183/ https://t.co/CKluADhzjv

    Post summary

    An unauthenticated reflected XSS flaw (CVE-2026-29183) in SiYuan’s dynamic icon API has been disclosed; no PoC, exploit code, patch, or active exploitation information is provided.

    0000048
    125 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more