CVE-2026-31809 | SiYuan up to 3.5.9 /api/icon/getDynamicIcon HasPrefix cross site scripting (GHSA-pmc9-f5qr-2pcr / EUVD-2026-10896)
A vulnerability identified as problematic has been detected in SiYuan up to 3.5.9. This impacts the function HasPrefix of the file /api/icon/getDynamicIcon. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-31809. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.