
CVE-2026-33066 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses http://lute.New() without calling SetSanitize(true), al… https://www.cve.org/CVERecord?id=CVE-2026-33066
Post summary
The post discloses a vulnerability in SiYuan's renderREADME function that lacks input sanitization, but no PoC, exploit, or active exploitation is reported.

