SiYuan has a Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-4343" }
"https://vuln.go.dev/ID/GO-2026-4343.json"