Stored XSS Vulnerability in SiYuan Notetaking Application
CVE-2026-87811
8.4HIGH
What is CVE-2026-87811?
The SiYuan Notetaking Application prior to version 3.8.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This issue arises from the inadequate encoding of HTML input value attributes that store notebook template paths. An attacker can exploit this vulnerability by crafting malicious template paths, which can lead to JavaScript execution upon a victim viewing the notebook configuration. This exploitation allows attackers to perform unauthorized same-origin API requests and manipulate the state of the application, posing significant security risks for users.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
