CVE-2026-40322
SiYuan could allow internal attacker to run malicious code on user computers
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
An internal attacker can take advantage of an issue in SiYuan by tricking a user into opening a malicious note. This grants the attacker control over the victim's machine, potentially allowing for the theft of sensitive data.