Stored Cross-Site Scripting Vulnerability in SiYuan Product by SiYuan Team
CVE-2026-66396

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66396?

The SiYuan product before version 3.7.2 presents a serious security issue by failing to properly escape the title-img Individual Attribute List value when rendering cover images in Gallery and Kanban. This vulnerability allows attackers with editor permissions to exploit stored cross-site scripting, enabling them to inject onload handlers that can execute arbitrary code in the Electron renderer. When users open affected documents, the repercussions can lead to full Node.js access, highlighting the need for immediate remediation.

Affected Version(s)

siyuan 0 < 3.7.2

siyuan 3.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hypnguyen1209
.