Stored Cross-Site Scripting Vulnerability in SiYuan by SiYuan
CVE-2026-84803
8.6HIGH
What is CVE-2026-84803?
SiYuan prior to version 3.8.2 has a vulnerability that allows stored cross-site scripting due to an insufficient blocklist for file extensions. This allows attackers to upload malicious files with extensions such as .xht, .ehtml, .xsl, .xbl, or .rdf. These files can lead to the execution of JavaScript, which may be leveraged to capture sensitive API tokens and potentially compromise workspaces.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
