Cross-Site Scripting Vulnerability in SiYuan Documentation Tool by SiYuan
CVE-2026-92986

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92986?

The SiYuan documentation tool, prior to version 3.8.4, is vulnerable to cross-site scripting due to improper handling of document titles in the backlink dock tree. Attackers can exploit this vulnerability by using the rename API or creating crafted notebooks that set malicious titles. This allows them to execute arbitrary scripts within the Electron renderer environment, which can lead to unauthorized command execution due to access to child processes.

Affected Version(s)

siyuan 0 < 3.8.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EVIL0RD
.