Stored XSS Vulnerability in SiYuan Knowledge Management System
CVE-2026-40322

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-40322?

The SiYuan Knowledge Management System, an open-source solution, has a vulnerability in versions 3.6.3 and below that can lead to stored Cross-Site Scripting (XSS). This issue arises from the improper rendering of Mermaid diagrams, where security level settings allow attacker-controlled JavaScript URLs to be included in the output. In environments using Electron, this can escalate to arbitrary code execution if a user interacts with a malicious Mermaid diagram. Users are advised to upgrade to version 3.6.4, where the issue has been addressed.

Affected Version(s)

siyuan < 3.6.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.