SiYuan Desktop <= v3.7.2 Vulnerabilities: Critical CVEs Discovered
SiYuan desktop versions before v3.7.3 have been found to contain multiple critical vulnerabilities, including a reflected cross-site scripting issue and SQL injection flaws. Users of affected versions are advised to upgrade immediately.
What happened
SiYuan desktop versions prior to v3.7.3 are affected by several critical vulnerabilities tracked as CVE-2026-66395, CVE-2026-69083, CVE-2026-69084, and CVE-2026-69085. CVE-2026-66395 is a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows arbitrary code execution via a crafted siyuan:// deep link. CVE-2026-69083 and CVE-2026-69084 are SQL injection vulnerabilities that enable attackers to execute arbitrary SQL statements and modify data across notebooks. These vulnerabilities have CVSS scores of 9.6 and 10.0, indicating critical severity. To mitigate these issues, users should upgrade to SiYuan desktop v3.7.3 or later.
The vulnerabilities were confirmed by multiple independent sources, including the National Vulnerability Database (NVD). The CVSS scores provided by VulnCheck indicate the severity of the issues, with CVSS-B scores of 9.4 for CVE-2026-66395 and 9.9 for CVE-2026-69083 and CVE-2026-69084. The primary sources should be consulted for the most accurate and detailed information on these vulnerabilities.
How 0Day mitigates this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.