CVE-2026-82654

Summary

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.

Affected Software

VendorProductVersion RangeStatus
siyuan-notesiyuan0 < 3.8.1affected
siyuan-notesiyuan3.8.1unaffected

Weaknesses

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References