SiYuan — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
June 22, 2026
Last Seen
August 4, 2026

SiYuan is an organization tracked by ThreatCluster, appearing in 4 threat clusters built from 4 intelligence report mentions.

SiYuan is a organization tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed June 22, 2026; most recent activity August 4, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-69083 AKAOMA CVE VULNERABILITIES / 22h SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data. — cve.akaoma.com · August 4, 2026
  • MCP as a Backdoor: CVE-2026-66012 — How a Missing Authorization Check in SiYuan's MCP Endpoint Turns Anonymous Readers into Administrators HB - Tailored Software Solutions / 1h The vulnerability, disclosed via GitHub Security Advisory GHSA-cvhv-7xhj-xjp8 on July 13, 2026, chains three independent defects in SiYuan’s kernel into an unauthenticated, network-reachable path to arbitrary workspace file read/write/delete, plaintext credential exfiltration, and remote code execution via plugin planting — www.hunt-benito.com · July 26, 2026
  • Critical SiYuan Stored XSS Flaw Enables RCE in Electron Desktop Client — Mallory.Ai · June 25, 2026
  • Critical RCE in SiYuan Bazaar Lets Malicious Packages Run OS Commands — Mallory.Ai · June 22, 2026

Frequently asked questions

What is SiYuan?

SiYuan is an organization tracked by ThreatCluster, appearing in 4 threat clusters built from 4 intelligence report mentions.

Is SiYuan still active?

The most recent intelligence report mentioning SiYuan on ThreatCluster is dated August 4, 2026. Activity was first observed June 22, 2026, giving a tracked span from then to August 4, 2026.

What is SiYuan associated with?

Across ThreatCluster reporting, SiYuan most frequently co-occurs with Data Breach, Sql Injection, Zero-day Exploit, CVE-2026-54158, CVE-2026-56395, among 12 tracked related entities.

What are the latest developments involving SiYuan?

The most significant recent cluster is “Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution” (7 articles · Updated June 25, 2026). SiYuan appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on SiYuan?

SiYuan appears in 4 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown