CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-34605

CVE-2026-34605: Reflected Cross-Site Scripting via SVG Namespace Bypass in SiYuan

Alon Barad
Alon Barad
Software Engineer

Apr 1, 2026·6 min read·60 visits

Executive Summary (TL;DR)

A flaw in SiYuan's `SanitizeSVG` function allows attackers to bypass XSS filters using XML namespace prefixes (e.g., `<x:script>`). This enables unauthenticated remote code execution within the victim's browser context. The issue affects versions 3.6.0 to 3.6.1 and is fixed in 3.6.2.

SiYuan personal knowledge management system versions 3.6.0 through 3.6.1 contain a high-severity Reflected Cross-Site Scripting (XSS) vulnerability. The flaw exists in the SVG sanitization logic within the `/api/icon/getDynamicIcon` endpoint, where an attacker can bypass tag blocklists using XML namespace prefixes. Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's session.

Vulnerability Overview

The SiYuan personal knowledge management system exposes an unauthenticated API endpoint at /api/icon/getDynamicIcon designed to serve dynamic SVG icons to clients. This endpoint accepts user-controlled input, presumably base64-encoded or directly parameterized SVG data, and reflects it back to the requester. To prevent malicious code execution, the application routes the input through a custom SanitizeSVG function introduced in version 3.6.0.

This sanitization function contains a critical logic flaw classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). The filter fails to account for XML namespace prefixes when evaluating HTML5/SVG node names. Consequently, an attacker can construct a payload that passes the backend validation but executes as a malicious script when parsed by the victim's browser.

The vulnerability requires user interaction to exploit, specifically requiring the victim to open a maliciously crafted URL pointing to the vulnerable SiYuan instance. Because the application serves the response with an image/svg+xml content type and lacks a restrictive Content Security Policy (CSP), the browser natively executes the embedded JavaScript. This grants the attacker full access to the application's DOM and the victim's active session.

Root Cause Analysis

The root cause of CVE-2026-34605 lies in a mismatch between how the backend Go HTML5 parser interprets SVG nodes and how a frontend browser's XML parser resolves them. The SanitizeSVG function processes incoming SVG data by parsing it into a node tree and walking the tree to filter out restricted tags. The security logic enforces a strict string matching algorithm, specifically targeting known dangerous elements like the <script> tag.

When the Go HTML5 parser encounters an element with an XML namespace prefix, such as <x:script xmlns:x="http://www.w3.org/2000/svg">, it records the node's tag name exactly as written: x:script. The sanitization routine subsequently compares this tag name against its blocklist. Since the literal string x:script does not equal script, the evaluation yields false, and the node is permitted to pass through the filter untouched.

Modern web browsers implement robust XML parsing engines that strictly adhere to W3C namespace specifications. When the browser receives the sanitized payload served with the image/svg+xml MIME type, it recognizes the xmlns:x attribute and resolves the x: prefix to the designated SVG namespace. The browser then strips the prefix during DOM construction, treating the element as a standard <script> tag and immediately executing its textual content as JavaScript.

Code Analysis and Data Flow

The underlying defect is a classic parser differential. The backend relies on a simplistic string comparison that fails to normalize XML local names before evaluation. A conceptual representation of the vulnerable logic demonstrates the flaw:

// Vulnerable Conceptual Implementation
func SanitizeSVG(input string) string {
    // Go HTML5 parser preserves the 'x:script' prefix
    nodeName := extractNodeName(input) 
    
    // Blocklist explicitly checks for 'script' without stripping prefixes
    if nodeName == "script" || nodeName == "iframe" || nodeName == "object" {
        return removeNode(input)
    }
    return input
}

To remediate this issue, the parsing logic must evaluate the local name of the element rather than the raw, prefixed tag name. The fix implemented in version 3.6.2 ensures that namespace prefixes are stripped or properly resolved before the blocklist comparison occurs. Alternatively, an allowlist approach strictly permitting only known-safe SVG structural elements entirely eliminates this class of bypass.

The following diagram illustrates the data flow of the exploit, demonstrating how the payload circumvents the backend filter but triggers execution in the frontend:

Exploitation Methodology

Exploitation of CVE-2026-34605 relies on delivering a crafted URL to an authenticated user of the targeted SiYuan instance. The attacker constructs an SVG payload containing the namespace-prefixed script tag. The payload definition establishes a custom namespace alias mapping back to the standard W3C SVG namespace.

The proof-of-concept payload demonstrates the required structural elements:

<svg xmlns="http://www.w3.org/2000/svg">
  <x:script xmlns:x="http://www.w3.org/2000/svg">alert('CVE-2026-34605')</x:script>
</svg>

The attacker typically base64-encodes or URL-encodes this payload depending on the specific parameter requirements of the getDynamicIcon endpoint. The resulting URL is distributed via phishing emails, direct messages, or embedded as a link in external forums. When the victim clicks the link, their browser issues a GET request to the vulnerable endpoint.

Because the endpoint is unauthenticated, the application processes the request regardless of the victim's session state. The server reflects the payload back to the client. If the victim has an active session within the SiYuan application on the same domain, the executed JavaScript gains full access to their session tokens, local storage, and the application's authenticated APIs.

Impact Assessment

The CVSS 4.0 assessment assigns this vulnerability a base score of 8.6, reflecting a High severity profile. The vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N highlights the primary risk factors: network-based attack vector, low complexity, no authentication requirement, and high impact on confidentiality and integrity.

The confidentiality impact (VC:H) stems from the attacker's ability to exfiltrate sensitive data. The executed JavaScript can read the victim's personal knowledge base, extract session cookies, and capture CSRF tokens. This data is silently transmitted to an attacker-controlled server using standard web APIs like fetch or XMLHttpRequest.

The integrity impact (VI:H) is equally severe. An attacker can leverage the compromised session to manipulate the user's data. This includes modifying existing notes, deleting workspaces, or injecting persistent XSS payloads into the stored knowledge base, effectively upgrading a reflected XSS vulnerability into a stored XSS vector. The availability impact (VA:L) remains low, as the attack primarily targets user data rather than the underlying server infrastructure.

Remediation and Mitigation Strategies

The primary and most effective remediation for CVE-2026-34605 is updating the SiYuan application to version 3.6.2 or later. The patch addresses the root cause by correcting the SVG sanitization logic to properly handle XML namespace prefixes, preventing the bypass condition.

For environments where immediate patching is not feasible, administrators must implement compensating controls. Deploying Web Application Firewall (WAF) rules to inspect incoming requests to the /api/icon/getDynamicIcon endpoint provides an effective temporary mitigation. The WAF should drop requests containing the xmlns attribute or namespace aliases (e.g., x:, ns1:) within the icon parameter payload.

Furthermore, implementing a strict Content Security Policy (CSP) provides architectural defense-in-depth against XSS vulnerabilities. Configuring the application to serve API responses with a CSP header that restricts script execution (e.g., default-src 'none') neutralizes the attack even if the backend parser fails to sanitize the payload. Administrators should also ensure the application configures the X-Content-Type-Options: nosniff header across all API endpoints.

Official Patches

siyuan-noteFixed Release 3.6.2

Technical Appendix

CVSS Score
8.6/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Systems

SiYuan Web ApplicationSiYuan Desktop Application (if utilizing the vulnerable endpoint for rendering)

Affected Versions Detail

Product
Affected Versions
Fixed Version
SiYuan
siyuan-note
>= 3.6.0, < 3.6.23.6.2
AttributeDetail
CWE IDCWE-79 (Improper Neutralization of Input During Web Page Generation)
Attack VectorNetwork
CVSS Score8.6 (High)
ImpactHigh Confidentiality, High Integrity
Exploit StatusProof of Concept Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1185Browser Session Hijacking
Collection
CWE-79
Cross-site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Known Exploits & Detection

Context ResearchProof of Concept demonstrating SVG namespace prefix bypass.

Vulnerability Timeline

Vulnerability publicly disclosed via GitHub Security Advisory.
2026-03-31
CVE-2026-34605 published to the National Vulnerability Database (NVD).
2026-03-31

References & Sources

  • [1]GitHub Security Advisory GHSA-73g7-86qr-jrg3
  • [2]SiYuan Release v3.6.2
  • [3]SiYuan Issue Tracker #17246
  • [4]NVD Record CVE-2026-34605
Related Vulnerabilities
CVE-2026-34605

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•17 minutes ago•CVE-2026-48597
8.2

CVE-2026-48597: Denial of Service via Atom Table Exhaustion in Elixir Tesla Client (Mint Adapter)

CVE-2026-48597 is a high-severity Denial of Service (DoS) vulnerability in the Elixir HTTP client library Tesla (specifically involving the Mint adapter) that allows an unauthenticated remote attacker to cause an unrecoverable crash of the Erlang Virtual Machine (BEAM). The flaw arises from the dynamic conversion of untrusted URL schemes into Erlang atoms without validation, leading to global atom table exhaustion.

Alon Barad
Alon Barad
2 views•8 min read
•43 minutes ago•CVE-2026-48598
2.1

CVE-2026-48598: Multipart Part Header Injection and Request Smuggling in elixir-tesla

An Improper Encoding or Escaping of Output vulnerability (CWE-116) in elixir-tesla allowed unauthenticated remote code execution or request smuggling via unescaped Content-Disposition parameters in multipart form-data requests.

Amit Schendel
Amit Schendel
4 views•5 min read
•about 1 hour ago•CVE-2026-49851
7.5

CVE-2026-49851: Algorithmic Complexity Denial of Service in Mistune Markdown Parser

CVE-2026-49851 is a high-severity algorithmic complexity vulnerability in the Mistune Markdown parser. Under specific conditions involving dense, unmatched nesting of opening square brackets, the parser fallback loops degrade from linear execution time to a worst-case quadratic complexity. This allows unauthenticated remote attackers to trigger complete CPU exhaustion and subsequent Denial of Service with a highly compact payload.

Alon Barad
Alon Barad
7 views•6 min read
•about 2 hours ago•CVE-2026-48862
8.2

CVE-2026-48862: Unbounded Resource Allocation via HTTP/2 PUSH_PROMISE Flooding in Mint

An allocation of resources without limits or throttling vulnerability in the Elixir Mint HTTP client library allows malicious HTTP/2 servers to trigger memory exhaustion and application denial of service. The flaw exists because Mint fails to validate server-push concurrency limits during the receipt of PUSH_PROMISE frames, deferring validation to the HEADERS phase. This allows a server to reserve an unlimited number of streams in the client's memory map.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-52778
9.8

CVE-2026-52778: Unauthenticated Remote Code Execution and ReDoS in YesWiki Bazar Formula Calculator

An unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki prior to version 4.6.6. The application attempts to validate mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This design leads to both Regular Expression Denial of Service (ReDoS) and Remote Code Execution (RCE) via validation bypass.

Alon Barad
Alon Barad
4 views•7 min read
•about 4 hours ago•CVE-2026-54651
5.5

CVE-2026-54651: Infinite Loop Vulnerability in pypdf Article Thread Parser

An infinite loop vulnerability exists in the pure-Python PDF library pypdf prior to version 6.13.1. When parsing or merging a crafted PDF file containing a cyclic Article/Thread structure, the library fails to exit its traversal loop. This causes the executing thread to hang indefinitely, leading to 100% CPU utilization and a denial of service. The vulnerability is tracked under CVE-2026-54651 and GHSA-g9xf-7f8q-9mcj, with a CVSS base score of 5.5. This technical report provides a root cause analysis, code review, exploitation vectors, and mitigation paths.

Alon Barad
Alon Barad
7 views•7 min read