Stored Cross-Site Scripting in SiYuan Personal Knowledge Management System
CVE-2026-23852
What is CVE-2026-23852?
SiYuan, a personal knowledge management system, is affected by a stored Cross-Site Scripting vulnerability in versions before 3.5.4. This vulnerability allows attackers to inject arbitrary HTML attributes into a block's icon attribute through the /api/attr/setBlockAttrs API. When exploited, the payload can be rendered in a dynamic icon feature without proper sanitization, potentially leading to stored XSS scenarios. Importantly, this flaw also opens the door to remote code execution (RCE) issues within the desktop environment, evading prior mitigations implemented for similar XSS vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
siyuan < 3.5.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
