XSS Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-40922

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-40922?

SiYuan, an open-source personal knowledge management system, suffered from a Cross-Site Scripting (XSS) vulnerability affecting versions 3.6.1 through 3.6.3. An incomplete fix for a previous XSS vulnerability allowed malicious authors to exploit the README rendering of bazaar packages. The Lute HTML sanitizer failed to adequately block iframe tags and improperly filtered srcdoc attributes containing raw HTML. This vulnerability permitted the execution of embedded scripts within the Electron context, giving attackers the ability to execute arbitrary code on the impacted user's machine. The issue was resolved in version 3.6.4.

Affected Version(s)

siyuan < 3.6.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.