
CVE-2026-40107 SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> t… https://www.cve.org/CVERecord?id=CVE-2026-40107
Post summary
CVE-2026-40107 affects SiYuan via Mermaid.js's 'loose' security level and htmlLabels true configuration, but no PoC, exploit, or patch is mentioned.

