Cross-Site Scripting Vulnerability in SiYuan Documentation Tool by SiYuan
CVE-2026-92986
8.6HIGH
What is CVE-2026-92986?
The SiYuan documentation tool, prior to version 3.8.4, is vulnerable to cross-site scripting due to improper handling of document titles in the backlink dock tree. Attackers can exploit this vulnerability by using the rename API or creating crafted notebooks that set malicious titles. This allows them to execute arbitrary scripts within the Electron renderer environment, which can lead to unauthorized command execution due to access to child processes.
Affected Version(s)
siyuan 0 < 3.8.4
