GHSA-jfm6-64hf-4hh9HighCVSS 8.8

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without...

Published
September 19, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

🔗 References (7)