Stored Cross-Site Scripting in SiYuan Personal Knowledge Management System
CVE-2026-23852

5.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23852?

SiYuan, a personal knowledge management system, is affected by a stored Cross-Site Scripting vulnerability in versions before 3.5.4. This vulnerability allows attackers to inject arbitrary HTML attributes into a block's icon attribute through the /api/attr/setBlockAttrs API. When exploited, the payload can be rendered in a dynamic icon feature without proper sanitization, potentially leading to stored XSS scenarios. Importantly, this flaw also opens the door to remote code execution (RCE) issues within the desktop environment, evading prior mitigations implemented for similar XSS vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

siyuan < 3.5.4

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.