Stored XSS in SiYuan Desktop Versions Prior to 3.8.4
CVE-2026-100641
8.6HIGH
What is CVE-2026-100641?
In SiYuan Desktop versions before 3.8.4, an unescaped stored flashcard block content allows for the injection of malicious scripts into the card manager. When executed, these scripts can run in a privileged renderer due to nodeIntegration being enabled and contextIsolation being disabled. This means that when an administrator views the card manager with attacker-supplied content, the injected code can be executed, potentially leading to arbitrary code execution on the host system.
Affected Version(s)
siyuan 0 < 3.8.4
siyuan 3.8.4
