CVE-2026-93923
8.8SiYuan · SiYuan
SiYuan versions through 3.8.4 are vulnerable to stored cross-site scripting via unescaped heading style attributes in the outline and bookmark dock, allowing malicious script execution.
Executive summary
SiYuan versions through 3.8.4 contain a stored cross-site scripting vulnerability that allows attackers to achieve full system access within the Electron renderer.
Vulnerability
The application fails to properly sanitize heading style attributes when rendering outline and bookmark dock HTML. This allows an attacker to inject malicious style values that execute in the context of the Electron renderer, effectively bypassing security boundaries.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high severity and potential for significant impact. Successful exploitation permits an attacker to execute arbitrary code with the full privileges of the Electron renderer, potentially leading to total system compromise, data theft, and unauthorized access to sensitive user notebooks.
Remediation
Immediate Action: Monitor official SiYuan release channels and apply the latest security update as soon as it becomes available to address this improper neutralization of input.
Proactive Monitoring: Review application logs for anomalous entries within notebook files or suspicious administrative endpoint requests that may suggest exploitation attempts.
Compensating Controls: Restrict access to untrusted notebook files and limit the ability of external users to interact with administrative endpoints until the software is patched.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for full system access through the Electron renderer, this vulnerability poses a severe risk to organizational security. Administrators should prioritize updating the SiYuan environment immediately upon the release of a patched version to prevent potential exploitation of this stored cross-site scripting flaw.
More SiYuan CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by EVIL0RD, per the CVE Program record.