Cross-Site Scripting Vulnerability in SiYuan Note-taking Application
CVE-2026-92985
8.6HIGH
What is CVE-2026-92985?
Versions of SiYuan prior to 3.8.4 have a vulnerability that allows attackers to exploit improperly escaped bookmark labels within imported notebook files. By crafting malicious .sy notebook files, attackers can inject unescaped HTML into bookmark attributes that may execute scripts in the Electron renderer environment. This susceptibility can lead to command execution through the child_process module, posing a significant security risk to users.
Affected Version(s)
siyuan 0 < 3.8.4
