CVE-2026-92986
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | 0 < 3.8.4 | affected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8509e7
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-c5h9-g2c6-fxjw
- https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-via-document-title
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.