DOM XSS and OS Command Execution Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-55570
9CRITICAL
What is CVE-2026-55570?
Prior to version 3.7.0, the SiYuan Personal Knowledge Management System suffers from a critical vulnerability that allows untrusted input fields, such as name, version, author, and description, to be improperly serialized into the data-obj HTML attribute. This flaw can lead to arbitrary HTML being injected when a malicious package name containing a single quote is processed. When executed in the desktop client (which runs with nodeIntegration enabled and contextIsolation disabled), this vulnerability escalates to remote code execution, posing a significant risk to users. The issue has been addressed in version 3.7.0, making it crucial for users to upgrade to this version to mitigate security risks.
Affected Version(s)
siyuan < 3.7.0
