Cross-Site Scripting Vulnerability in SiYuan by SiYuan Technology
CVE-2026-75917
What is CVE-2026-75917?
SiYuan versions prior to v3.7.4 are susceptible to a cross-site scripting flaw. Specifically, the vulnerability lies in the file-tree picker's hover-tooltip generation where user-controlled document metadata fields are improperly concatenated into the aria-label HTML attribute without appropriate escaping. This oversight allows an attacker to inject malicious HTML when a document metadata field contains a double quote. Given that every SiYuan Electron BrowserWindow operates with nodeIntegration enabled and contextIsolation disabled, the injected HTML can trigger arbitrary OS command execution upon a simple mouse hover over the affected document entry. Malicious documents can be disseminated through various means, including sharing and synchronization, posing a significant risk to users.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
