Description
SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.
Published: 2026-09-08
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

SiYuan versions prior to 3.8.2 execute code that is pasted from a specially crafted clipboard entry. The application trusts the attacker‑writable text/siyuan MIME type and skips the usual sanitization step in its paste handler. This omission allows a payload containing JavaScript to run with full Node.js privileges through the Electron main process, granting the attacker unrestricted access to the local filesystem, network, and other system resources. The weakness is a classic reflected input flaw that permits arbitrary script execution, represented by CWE‑79.

Affected Systems

The vulnerability affects the Siyuan note application from B3LOG (siyuan-note:siyuan). Users installing releases older than 3.8.2 are impacted; versions 3.8.2 and newer are not susceptible to this specific flaw.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. An attacker does not need authentication or privileged access; they only need to create a malicious web page or manipulate the clipboard on a machine where SiYuan is installed. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the flaw is technically straightforward and executable in a typical desktop environment. The vulnerability is not listed in the CISA KEV catalog at present. Based on the description, the likely attack vector is inferred from the description and involves delivering malicious clipboard content to the user, who must paste it into SiYuan.

Generated by OpenCVE AI on September 8, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.8.2 or newer, which resolves the clipboard sanitization flaw.
  • Disallow or minimize usage of the text/siyuan clipboard MIME type in untrusted contexts; consider disabling clipboard access for non‑trusted applications.
  • Avoid pasting content from unknown or suspicious sources into SiYuan; whenever possible, inspect clipboard data before pasting.

Generated by OpenCVE AI on September 8, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Tue, 08 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.
Title SiYuan before 3.8.2 Remote Code Execution via Clipboard
First Time appeared B3log
B3log siyuan
Weaknesses CWE-79
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:03:19.971Z

Reserved: 2026-09-08T10:58:25.497Z

Link: CVE-2026-86712

cve-icon Vulnrichment

Updated: 2026-09-10T14:27:46.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T12:16:59.990

Modified: 2026-09-10T16:18:03.470

Link: CVE-2026-86712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')