Crossfyre

Disclosures

Vulnerabilities we found in other people's software and reported to the people who maintain it.

Advisories filed
25
covering 26 findings
Published by the maintainer
1
listed in full below
Still with the maintainer
21
3 fixed and under embargo
Closed without a fix
3
2 we withdrew ourselves

No CVE has been assigned to any of these yet. Four have one requested by the maintainer, which is not the same thing, and this page will say so plainly until an identifier actually exists.

Published

Reports the maintainer has fixed and disclosed. The link is the record; ours is only the summary.

1 disclosure

  • SiYuan Moderate, 6.5

    One GET to the dynamic icon endpoint expands an uncapped template function map until the kernel process is killed for exhausting memory. Reachable by any publish reader, and by anyone at all on a default publish service.

    Reported
    22 Sept 2026
    Published
    24 Sept 2026
    CVE
    none assigned

Why the rest is a number

A report gets its own entry here once the maintainer has published it, and not before. Naming a project next to an unfixed authorization bug tells an attacker which product to look at and roughly where to look, which defeats the purpose of having reported it quietly. Three of the open ones are additionally under an embargo the maintainer asked for, so they are not broken out by date or severity either: a fix date and a severity are enough to narrow a search.

That also rules out the obvious compromise, a list of the projects with nothing tying any of them to a particular finding. Eleven names under a heading that says we found authorization bugs in them is the same disclosure with an extra step, and two of these went through a bounty platform whose programs forbid disclosure without written permission. The counts move as maintainers work through them, and each row appears in full the day its advisory goes public.

Two of the closed ones we withdrew ourselves after the premise did not survive a second look: one behaviour turned out to be documented, and one stored-XSS report rested on fields that are not attacker-controllable. They stay counted, because a page that only counts the hits is a page that has learned to drop the misses.

Looking for the other direction, reporting something in Crossfyre itself? That is our security policy. Bugs we found in our own product are written up under publications, once they were fixed.