XSS Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-40922
5.3MEDIUM
What is CVE-2026-40922?
SiYuan, an open-source personal knowledge management system, suffered from a Cross-Site Scripting (XSS) vulnerability affecting versions 3.6.1 through 3.6.3. An incomplete fix for a previous XSS vulnerability allowed malicious authors to exploit the README rendering of bazaar packages. The Lute HTML sanitizer failed to adequately block iframe tags and improperly filtered srcdoc attributes containing raw HTML. This vulnerability permitted the execution of embedded scripts within the Electron context, giving attackers the ability to execute arbitrary code on the impacted user's machine. The issue was resolved in version 3.6.4.
Affected Version(s)
siyuan < 3.6.4
