CVE-2026-32940Disclosure(b3log / siyuan)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses data:text/xml and data:application/xml, both of which can render SVG with JavaScript execution. The unauthenticated /api/icon/getDynamicIcon endpoint serves user-controlled input (via the content parameter) directly into SVG markup using fmt.Sprintf with no escaping, served as Content-Type: image/svg+xml. This creates a click-through XSS: a victim navigates to a crafted URL, sees an SVG with an injected link, and clicking it triggers JavaScript via the bypassed MIME types. The attack requires direct navigation to the endpoint or <object>/<embed> embedding, since <img> tag rendering in the frontend doesn't allow interactive links. This issue has been fixed in version 3.6.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-184

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-20: 5Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 5Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-205
Disclosure4Patch1
2026-03-221
Disclosure1
Full discourse6 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32940 - Critical SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attribut... https://www.thehackerwire.com/vulnerability/CVE-2026-32940/ https://t.co/uRae69w7Ma

    Post summary

    CVE‑2026-32940 details a critical flaw in SiYuan’s SanitizeSVG function due to an incomplete blocklist of data URLs in href attributes, as disclosed by external resources.

    0000030
    142 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32940: SiYuan has a SanitizeSVG bypass ... SiYuan's SVG sanitizer forgot data:text/xml can execute JS too—unauthenticated /api/icon/getDynamicIcon serves user inp... https://zerodaysignal.com/vulnerability/CVE-2026-32940 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-32940, a SanitizeSVG bypass in SiYuan that permits unauthenticated JavaScript execution via data:text/xml in the /api/icon/getDynamicIcon endpoint, and supplies a link for further details.

    0000067
    155 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SanitizeSVG bypass (CVE-2026-32940) has been identified in `SiYuan`, allowing `data:text/xml` to bypass sanitization. This incomplete fix may lead to client-side code execution. Monitor for updates. #SiYuan #Vulnerability #XSS https://www.pulsepatch.io/posts/cve-2026-32940-siyuan-svg-bypass

    Post summary

    CVE‑2026‑32940 is a SanitizeSVG bypass in SiYuan via `data:text/xml`, potentially enabling client‑side code execution; the post reports the vulnerability but does not provide PoC, exploit code, or patch information.

    0000033
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32940 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+x… https://www.cve.org/CVERecord?id=CVE-2026-32940

    Post summary

    The post reports the discovery of a CVE (CVE-2026-32940) in SiYuan's SanitizeSVG engine, noting an incomplete blocklist that misses certain data URL schemes in versions 3.6.0 and earlier.

    00000113
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32940 Unauthenticated Click-Through XSS in SiYuan Knowledge Management System 3.6.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32940

    Post summary

    The post announces CVE-2026-32940, detailing an unauthenticated click-through XSS vulnerability in SiYuan Knowledge Management System 3.6.0, with no exploitation, patch, or PoC information provided.

    0000036
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32940: CRITICAL] SiYuan users are urged to update to version 3.6.1 due to a cyber security flaw in previous versions. A vulnerability allows click-through XSS attacks via unescaped SVG input.#cve,CVE-2026-32940,#cybersecurity https://cvefind.com/CVE-2026-32940

    Post summary

    A critical click‑through XSS flaw in SiYuan is discovered via unescaped SVG input, prompting users to update to version 3.6.1.

    0000050
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more