Stored Cross-Site Scripting in SiYuan Note by SiYuan
CVE-2026-93923
8.6HIGH
What is CVE-2026-93923?
SiYuan Note up to version 3.8.4 is susceptible to stored cross-site scripting attacks due to improper escaping of heading style attributes in rendered HTML for outlines and bookmarks. This weakness allows attackers to deliver malicious notebooks or utilize administrative endpoints to inject harmful style values. Once executed, these injected scripts operate in the Electron renderer, potentially providing full system access to the adversaries, posing significant security risks to users.
Affected Version(s)
siyuan 0 <= 3.8.4
