This record is a duplicate; use CVE-2026-56397 instead.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Install SiYuan version 3.6.1 or later, which remediates the metadata sanitization flaw.
- Limit Bazaar marketplace usage to trusted or verified authors, or disable the marketplace entirely if not needed for your workflow.
- Configure the Electron application to disable nodeIntegration by setting the relevant webPreferences option to false, preventing execution of injected scripts from untrusted content.
Generated by OpenCVE AI on June 21, 2026 at 16:35 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Thu, 17 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands. | This record is a duplicate; use CVE-2026-56397 instead. |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 22 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands. | |
| Title | SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T16:04:58.400Z
Reserved: 2026-06-21T12:37:58.434Z
Link: CVE-2026-56395
Updated:
Status : Rejected
Published: 2026-06-21T14:16:26.530
Modified: 2026-09-17T17:16:44.410
Link: CVE-2026-56395
No data.
OpenCVE Enrichment
Updated: 2026-06-21T19:30:16Z
No weakness.