CVE-2026-23850
EUVD-2026-329219.01.2026, 20:15
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| b3log | siyuan | 𝑥 < 3.5.4 |
𝑥
= Vulnerable software versions
References