Stored XSS Vulnerability in SiYuan Knowledge Management System
CVE-2026-40322
9.1CRITICAL
What is CVE-2026-40322?
The SiYuan Knowledge Management System, an open-source solution, has a vulnerability in versions 3.6.3 and below that can lead to stored Cross-Site Scripting (XSS). This issue arises from the improper rendering of Mermaid diagrams, where security level settings allow attacker-controlled JavaScript URLs to be included in the output. In environments using Electron, this can escalate to arbitrary code execution if a user interacts with a malicious Mermaid diagram. Users are advised to upgrade to version 3.6.4, where the issue has been addressed.
Affected Version(s)
siyuan < 3.6.4
