Stored Cross-Site Scripting Vulnerability in SiYuan by SiYuan Note
CVE-2026-87813

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87813?

SiYuan versions prior to 3.8.2 are susceptible to a stored cross-site scripting vulnerability. This issue arises from the interpolation of asset filenames into HTML without proper escaping, allowing authenticated attackers to inject malicious markup. When users search for these assets, the crafted asset filenames activate the injected JavaScript in the victim's browser. This can lead to unauthorized API requests and manipulation of the application state, posing significant security risks to users.

Affected Version(s)

siyuan 0 < 3.8.2

siyuan 3.8.2

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.