github TypeScript not analyzable

siyuan-note/siyuan

github

not analyzable — repository too large to download in full

A privacy-first, self-hosted, fully open source personal knowledge management software, written in typescript and golang.

maintainer
siyuan-note
license
AGPL-3.0
first seen
2026-06-24
last seen
2026-08-01
releases · 30d
12
short id
risk 42/100 · heuristic grade
C elevated

Source not yet analyzed — this grade rests on attested signals (CVEs, supply-chain) only. It is a floor: reading the code could raise it, not lower it.

  • vulnerabilities attested + 50
  • trust mitigators mixed − 8

attested mixed

The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.

graded 4m ago · see ecosystem CVEs →

risk trajectory 1 movements
  • A · 0 C · 42
vulnerabilities 20 CVEs · grade factor +50
CRITICAL
Attribute View cell values: stored XSS to RCE (incomplete HTML escaping in renderCell) affects ["<= 3.7.1"]
CRITICAL
`siyuan://` tab icon XSS to RCE affects ["<= 3.7.1"]
CRITICAL
Store XSS To Rce via Asset.render EPSS 0% CVE-2026-59855 affects ["<=3.6.5"]
CRITICAL
Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG … EPSS 0% CVE-2026-59833 affects ["<= 3.6.5"]
CRITICAL
Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (incompl … EPSS 0% CVE-2026-55570 affects ["<= v3.6.5"]
CRITICAL
Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, leading to arbitrary command ex … EPSS 0% CVE-2026-54759 affects ["<= 3.6.5"]
CRITICAL
Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content EPSS 0% CVE-2026-50551 affects ["<= 3.6.5"]
CRITICAL
Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() EPSS 0% CVE-2026-54158 affects ["<= 3.6.5"]
CRITICAL
Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() EPSS 0% CVE-2026-54067 affects ["<= 3.6.5"]
CRITICAL
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored X … EPSS 0% CVE-2026-45375 affects ["<= 3.6.5"]
CRITICAL
URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSS => … EPSS 1% CVE-2026-44588 affects ["<= 3.6.5"]
CRITICAL
Stored XSS via Attribute View name to Electron renderer RCE in SiYuan EPSS 1% CVE-2026-44670 affects ["<= 3.6.5"]
CRITICAL
SiYuan Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE EPSS 0% CVE-2026-40322 affects ["<=3.6.3"]
CRITICAL
Remote Code Execution in the Electron desktop client via stored XSS in synced table captions EPSS 1% CVE-2026-39846 affects ["<=v3.6.3"]
CRITICAL
Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection EPSS 0% CVE-2026-34449 affects ["<= 3.6.1"]
CRITICAL
Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in th … EPSS 0% CVE-2026-34448 affects ["3.6.1"]
CRITICAL
Directory traversal within the publishing service EPSS 1% CVE-2026-33670 affects ["3.6.1"]
CRITICAL
Arbitrary document reading within the publishing service EPSS 1% CVE-2026-33669 affects ["3.6.1"]
CRITICAL
Stored XSS to RCE via Unsanitized Bazaar Package Metadata EPSS 1% CVE-2026-33067 affects ["SiYuan <= 3.5.9"]
CRITICAL
Stored XSS to RCE via Unsanitized Bazaar README Rendering EPSS 1% CVE-2026-33066 affects ["SiYuan <= 3.5.9"]
tool safety all quiet

No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.

embed badge readme-ready
live risk-grade badge preview [![MCP Observatory risk grade](https://mcpobservatory.com/servers/github:siyuan-note/siyuan/badge.svg)](https://mcpobservatory.com/servers/github:siyuan-note/siyuan/security)

Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of siyuan-note.