Stored Cross-Site Scripting Vulnerability in SiYuan by SiYuan Note
CVE-2026-87813
8.4HIGH
What is CVE-2026-87813?
SiYuan versions prior to 3.8.2 are susceptible to a stored cross-site scripting vulnerability. This issue arises from the interpolation of asset filenames into HTML without proper escaping, allowing authenticated attackers to inject malicious markup. When users search for these assets, the crafted asset filenames activate the injected JavaScript in the victim's browser. This can lead to unauthorized API requests and manipulation of the application state, posing significant security risks to users.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
