Cross-Site Scripting Vulnerability in SiYuan by SiYuan Technology
CVE-2026-75917

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75917?

SiYuan versions prior to v3.7.4 are susceptible to a cross-site scripting flaw. Specifically, the vulnerability lies in the file-tree picker's hover-tooltip generation where user-controlled document metadata fields are improperly concatenated into the aria-label HTML attribute without appropriate escaping. This oversight allows an attacker to inject malicious HTML when a document metadata field contains a double quote. Given that every SiYuan Electron BrowserWindow operates with nodeIntegration enabled and contextIsolation disabled, the injected HTML can trigger arbitrary OS command execution upon a simple mouse hover over the affected document entry. Malicious documents can be disseminated through various means, including sharing and synchronization, posing a significant risk to users.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
hey-raghav
.