Stored XSS Vulnerability in SiYuan by SiYuan Note
CVE-2026-100643
8.5HIGH
What is CVE-2026-100643?
Versions of SiYuan prior to v3.8.4 contain a vulnerability that fails to properly escape four stored Attribute View values within textarea elements. This oversight enables authenticated attackers to inject malicious JavaScript by altering field descriptions, template sources, select option descriptions, or footer calculation templates. When other users access affected database menus, the injected JavaScript can execute, and in the Electron desktop application with nodeIntegration enabled, this may lead to command execution with elevated privileges of the SiYuan process.
Affected Version(s)
siyuan 2.10.8 < 3.8.4
siyuan 3.8.4
