home.social

#siyuan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #siyuan, aggregated by home.social.

fetched live
  1. CVE-2026-82234 - High-severity SSRF in SiYuan via DNS rebinding, exposing internal services and cloud metadata. CVSS 8.2. Update to v3.8.1 immediately. #CVE #SiYuan #infosec

    valtersit.com/cve/CVE-2026-822

  2. CVE-2026-74800 - Stored XSS in SiYuan. Missing headers allow script execution with full kernel API access. CVSS 9.0. Unpatched. Update or restrict file uploads now. #CVE #SiYuan #infosec

    valtersit.com/cve/CVE-2026-748

  3. CVE-2026-73056 - Critical auth bypass in SiYuan kernel <3.7.4. Unauthenticated attackers can brute-force API tokens via CheckAuth() middleware, no lockout. CVSS 9.8. Update immediately. #CVE #SiYuan #infosec

    valtersit.com/cve/CVE-2026-730

  4. CVE-2026-72798 - High severity info disclosure in SiYuan. Unpatched v3.7.4 lets anonymous readers access hidden database content via related-database bypass. CVSS 8.6. Update immediately. #CVE #SiYuan #infosec

    valtersit.com/cve/CVE-2026-727