Stored XSS Vulnerability in SiYuan by SiYuan Note
CVE-2026-100643

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100643?

Versions of SiYuan prior to v3.8.4 contain a vulnerability that fails to properly escape four stored Attribute View values within textarea elements. This oversight enables authenticated attackers to inject malicious JavaScript by altering field descriptions, template sources, select option descriptions, or footer calculation templates. When other users access affected database menus, the injected JavaScript can execute, and in the Electron desktop application with nodeIntegration enabled, this may lead to command execution with elevated privileges of the SiYuan process.

Affected Version(s)

siyuan 2.10.8 < 3.8.4

siyuan 3.8.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Smavl
.