Reflected Cross-Site Scripting in SiYuan Desktop by SiYuan
CVE-2026-66395
9.4CRITICAL
What is CVE-2026-66395?
SiYuan Desktop prior to version 3.7.2 exhibits a reflected cross-site scripting vulnerability through its bazaar plugin's readme handler. By leveraging this flaw, attackers can craft malicious deep links using the siyuan:// protocol that allow them to execute arbitrary HTML code. This is possible via the plugin name parameter, which, when processed by the insecurely configured Electron renderer, risks exposing the application to unauthorized Node.js access, thereby compromising user data and application integrity.
Affected Version(s)
siyuan 0 < 3.7.2
siyuan 3.7.2
