Description
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting affecting rendered HTML
Action: Apply patch
AI Analysis

Impact

The bug in SiYuan versions up to 3.8.4 causes heading style attributes to be rendered without escaping. This flaw permits stored cross‑site scripting; attackers can insert malicious style values that execute in the Electron renderer, granting full system access. The issue aligns with the classic XSS weakness (CWE‑79) that allows arbitrary code execution in the application context.

Affected Systems

The affected product is the SiYuan desktop note‑taking application seen in the cpe series for siyuan‑note. Versions through 3.8.4 are vulnerable when notebooks are opened or administrative endpoints are invoked. No later releases are listed as affected, and the vendor has identified the vulnerable code in Tree.ts and render.go files.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability is rated high. EPSS data is not available, but the attacker only needs a crafted notebook or API call to inject the payload, and the browser context of the Electron app then runs scripts with the user’s privileges. The flaw is not yet listed in the CISA KEV database, yet it delivers complete remote code execution within the desktop environment, making it a serious risk for any user who opens or creates potentially malicious notebooks.

Generated by OpenCVE AI on September 19, 2026 at 10:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SiYuan to the latest release that fixes the escape bug.
  • Disable or restrict heading style customization if an upgrade is not immediately possible, and limit notebook import/export from untrusted sources.
  • Protect administrative endpoints behind strong authentication and role‑based access controls so only authorized users can inject content.
  • Periodically audit existing notebooks for injected style attributes and cleanse or remove any that contain malicious code.

Generated by OpenCVE AI on September 19, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.
Title SiYuan through 3.8.4 Stored XSS via Heading Style Attribute
First Time appeared B3log
B3log siyuan
Weaknesses CWE-79
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:39:08.068Z

Reserved: 2026-09-18T21:57:00.454Z

Link: CVE-2026-93923

cve-icon Vulnrichment

Updated: 2026-09-21T15:39:00.694Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T00:16:57.963

Modified: 2026-09-21T16:17:28.387

Link: CVE-2026-93923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')