Stored Cross-Site Scripting Vulnerability in SiYuan Product by SiYuan Team
CVE-2026-66396
9.3CRITICAL
What is CVE-2026-66396?
The SiYuan product before version 3.7.2 presents a serious security issue by failing to properly escape the title-img Individual Attribute List value when rendering cover images in Gallery and Kanban. This vulnerability allows attackers with editor permissions to exploit stored cross-site scripting, enabling them to inject onload handlers that can execute arbitrary code in the Electron renderer. When users open affected documents, the repercussions can lead to full Node.js access, highlighting the need for immediate remediation.
Affected Version(s)
siyuan 0 < 3.7.2
siyuan 3.7.2
