Stored XSS Vulnerability in SiYuan Before v3.8.1 by SiYuan Development
CVE-2026-82654

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82654?

An improper handling of block attributes in SiYuan before version 3.8.1 allows attackers to insert malicious HTML or script tags into block names, aliases, and memo fields. This exploitation can lead to stored XSS attacks, where the harmful code executes whenever a user accesses documents that reference the compromised blocks, potentially compromising user data and session security.

Affected Version(s)

siyuan 0 < 3.8.1

siyuan 3.8.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
crypto-nidh
.