CVE-2026-31809Disclosure(b3log / siyuan)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: prefix using strings.HasPrefix(). However, inserting ASCII tab (	), newline (
), or carriage return (
) characters inside the javascript: string bypasses this prefix check. Browsers strip these characters per the WHATWG URL specification before parsing the URL scheme, so the JavaScript still executes. This allows an attacker to inject executable JavaScript into the unauthenticated /api/icon/getDynamicIcon endpoint, creating a reflected XSS. This is a second bypass of the fix for CVE-2026-29183 (fixed in v3.5.9). This vulnerability is fixed in 3.5.10.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-04-06: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-04-06: 103-1003-1204-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-31809 - medium 🚨 SiYuan <= v3.5.9 - Cross Site Scripting > SiYuan v3.5.10 contains a reflected XSS caused by improper sanitization of javascript... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-31809 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet reveals CVE-2026-31809 as a medium‑severity reflected XSS in SiYuan versions up to 3.5.9, with brief technical details and a link to a reference library page.

    00011151
    916 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 SiYuan, SVG Sanitizer Bypass via Whitespace in URI, #CVE-2026-31809 (Medium) https://dailycve.com/siyuan-svg-sanitizer-bypass-via-whitespace-in-uri-cve-2026-31809-medium/

    Post summary

    The post announces CVE-2026-31809, a medium‑severity SVG sanitizer bypass in SiYuan, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000039
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31809 SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: prefix using string… https://www.cve.org/CVERecord?id=CVE-2026-31809

    Post summary

    The excerpt announces that SiYuan's SVG sanitizer before version 3.5.10 fails to properly validate ‘javascript:’ href attributes, exposing a potential vulnerability.

    00000189
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more