CVE-2026-31807 | SiYuan up to 3.5.9 Endpoint /api/icon/getDynamicIcon cross site scripting (GHSA-5hc8-qmg8-pw27 / EUVD-2026-10892)
A vulnerability categorized as problematic has been discovered in SiYuan up to 3.5.9. This affects an unknown function of the file /api/icon/getDynamicIcon of the component Endpoint. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-31807. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.