8.6

CVSS4.0

CVE-2026-34605 - SiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthentica…

SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-prefixed element names such as <x:script xmlns:x=…

📅 Published: March 31, 2026, 9:50 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

8.6

CVSS3.1

CVE-2026-34585 - SiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, packa…

📅 Published: March 31, 2026, 9:47 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

9.7

CVSS3.1

CVE-2026-34449 - SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a Java…

📅 Published: March 31, 2026, 9:45 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

9.1

CVSS3.1

CVE-2026-34448 - SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execut…

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary …

📅 Published: March 31, 2026, 9:44 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

7.5

CVSS3.1

CVE-2026-34453 - SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors …

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess…

📅 Published: March 31, 2026, 9:43 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

6.3

CVSS4.0

CVE-2026-34451 - Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not …

📅 Published: March 31, 2026, 9:35 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

4.8

CVSS4.0

CVE-2026-34450 - Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK created memory files with mode 0o666, leaving them world-readable on systems with a standard umask and wor…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

5.8

CVSS4.0

CVE-2026-34452 - Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returne…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 3, 2026, 4:08 p.m.

5.4

CVSS3.1

CVE-2026-34442 - FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Reso…

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-34443 - FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR …

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 343040
Page 157 of 34,304
« previous page » next page
Filters