CVE-2026-32940 | SiYuan up to 3.6.0 Endpoint /api/icon/getDynamicIcon cross site scripting (GHSA-6865-qjcf-286f)
A vulnerability was found in SiYuan up to 3.6.0. It has been declared as problematic. This vulnerability affects unknown code of the file /api/icon/getDynamicIcon of the component Endpoint. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-32940. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.