CVE-2026-40107
MEDIUM WAF: Medium
CVSS 6.5
Published: 2026-04-09
CWE-918
SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, tags with src attributes survive Mermaid's internal DOMPurify and land in SVG
WAF Coverage Analysis
Server-Side Request Forgery (SSRF)
Medium WAF Coverage
OWASP: A10:2021 SSRF
934xxx - Node.js / Generic Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| b3log | siyuan | up to 3.6.4 |
References
- github.com (Exploit, Vendor Advisory)