The Hacker Wire@TheHackerWireDisclosure
CVE‑2026-32940 details a critical flaw in SiYuan’s SanitizeSVG function due to an incomplete blocklist of data URLs in href attributes, as disclosed by external resources.
0day Signal@0dayPublishingDisclosure
The post announces CVE-2026-32940, a SanitizeSVG bypass in SiYuan that permits unauthenticated JavaScript execution via data:text/xml in the /api/icon/getDynamicIcon endpoint, and supplies a link for further details.
PulsePatch.io@pulsepatchioDisclosure
CVE‑2026‑32940 is a SanitizeSVG bypass in SiYuan via `data:text/xml`, potentially enabling client‑side code execution; the post reports the vulnerability but does not provide PoC, exploit code, or patch information.
CVE@CVEnewDisclosure
The post reports the discovery of a CVE (CVE-2026-32940) in SiYuan's SanitizeSVG engine, noting an incomplete blocklist that misses certain data URL schemes in versions 3.6.0 and earlier.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE-2026-32940, detailing an unauthenticated click-through XSS vulnerability in SiYuan Knowledge Management System 3.6.0, with no exploitation, patch, or PoC information provided.
CVEFind.com@CveFindComPatch
A critical click‑through XSS flaw in SiYuan is discovered via unescaped SVG input, prompting users to update to version 3.6.1.