References https://ddpoc.com/DVB-2026-11039.html https://nvd.nist.gov/vuln/detail/CVE-2026-34605 https://nvd.nist.gov/vuln/detail/CVE-2026-31807 https://github.com/siyuan-note/siyuan/security/advisories/GHSA-73g7-86qr-jrg3 https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5hc8-qmg8-pw27 https://www.sentinelone.com/vulnerability-database/cve-2026-34605/ https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-31807.yaml
Related Vulnerabilities思源笔记存在未授权路径遍历漏洞(CVE-2026-33476)PoCCVE-2026-31807: SiYuan <= v3.5.9 - SVG Animate Element XSS链滴科技 思源笔记 需授权 路径遍历漏洞 可导致任意文件读取