Reflected Cross-Site Scripting in SiYuan Desktop by SiYuan
CVE-2026-66395

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66395?

SiYuan Desktop prior to version 3.7.2 exhibits a reflected cross-site scripting vulnerability through its bazaar plugin's readme handler. By leveraging this flaw, attackers can craft malicious deep links using the siyuan:// protocol that allow them to execute arbitrary HTML code. This is possible via the plugin name parameter, which, when processed by the insecurely configured Electron renderer, risks exposing the application to unauthorized Node.js access, thereby compromising user data and application integrity.

Affected Version(s)

siyuan 0 < 3.7.2

siyuan 3.7.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hypnguyen1209
.