Cross-Site Scripting in SiYuan Personal Knowledge Management System
CVE-2026-54070

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-54070?

In SiYuan, prior to version 3.7.0, an XSS vulnerability exists due to inadequate sanitization when rendering Bazaar package README files. The vulnerability arises from the use of the lute sanitizer, which allows certain modern event handler attributes to pass through unchecked. This flaw enables an attacker to inject malicious JavaScript into a README file that can then be executed in the context of an authenticated administrator session. As a result, an attacker can manipulate the workspace of the Administrator upon viewing the package listing, posing serious security risks. The vulnerability was addressed in version 3.7.0, highlighting the importance of maintaining updated software to mitigate such risks.

Affected Version(s)

siyuan < 3.7.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.