CVE-2026-31809 identifies a reflected Cross-Site Scripting (XSS) vulnerability in SiYuan personal knowledge management system versions prior to 3.5.10. This flaw allows an attacker to inject executable JavaScript into the unauthenticated /api/icon/getDynamicIcon endpoint by bypassing the SVG sanitizer's `javascript:` prefix check in `href` attributes. With a CVSS score of 6.1 (Medium), the vulnerability has a network attack vector and low attack complexity, requiring user interaction but no privileges, potentially leading to low impacts on confidentiality and integrity. There is no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal. This issue represents a second bypass of a previous fix and is resolved in SiYuan version 3.5.10.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.10CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.