Impact
The bug in SiYuan versions up to 3.8.4 causes heading style attributes to be rendered without escaping. This flaw permits stored cross‑site scripting; attackers can insert malicious style values that execute in the Electron renderer, granting full system access. The issue aligns with the classic XSS weakness (CWE‑79) that allows arbitrary code execution in the application context.
Affected Systems
The affected product is the SiYuan desktop note‑taking application seen in the cpe series for siyuan‑note. Versions through 3.8.4 are vulnerable when notebooks are opened or administrative endpoints are invoked. No later releases are listed as affected, and the vendor has identified the vulnerable code in Tree.ts and render.go files.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is rated high. EPSS data is not available, but the attacker only needs a crafted notebook or API call to inject the payload, and the browser context of the Electron app then runs scripts with the user’s privileges. The flaw is not yet listed in the CISA KEV database, yet it delivers complete remote code execution within the desktop environment, making it a serious risk for any user who opens or creates potentially malicious notebooks.
OpenCVE Enrichment