Description
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via stored XSS in Electron renderer
Action: Immediate Patch
AI Analysis

Impact

SiYuan versions up to 3.8.4 render notebook names as raw HTML in the Daily Note picker dialog. An attacker can create a notebook whose name contains JavaScript that is executed when the picker opens, giving the script Node.js access within the Electron context. This flaw allows the attacker to run arbitrary operating system commands on the host machine, effectively achieving remote code execution. The vulnerability is a stored cross‑site scripting flaw (CWE‑79).

Affected Systems

The affected product is SiYuan Note (product name 'siyuan') from the vendor b3log. All releases up to and including version 3.8.4 are impacted. No other vendors or products are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is unavailable and the CVE is not listed in CISA’s KEV catalog, so public exploitation data is scarce. The attack vector is inferred to require the victim to open the Daily Note picker after a malicious notebook has been created, which can be performed by a local user or by any user who opens the application containing the vulnerable notebook. Because the payload runs with Node.js privileges, a single successful exploitation can lead to full system compromise. The risk remains significant until a fix is applied.

Generated by OpenCVE AI on September 19, 2026 at 10:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.8.5 or later to eliminate the stored XSS flaw.
  • If an upgrade is not immediately possible, avoid creating or opening notebooks whose names contain HTML markup and refrain from opening the Daily Note picker while such notebooks exist.
  • Implement output escaping or input validation for notebook names in your deployment, ensuring that HTML tags are rendered as plain text rather than executed code.

Generated by OpenCVE AI on September 19, 2026 at 10:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
Title SiYuan through 3.8.4 Stored XSS via notebook names
First Time appeared B3log
B3log siyuan
Weaknesses CWE-79
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T15:53:10.055Z

Reserved: 2026-09-18T21:57:00.085Z

Link: CVE-2026-93922

cve-icon Vulnrichment

Updated: 2026-09-22T15:53:00.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T00:16:57.783

Modified: 2026-09-22T16:18:14.603

Link: CVE-2026-93922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')