Siyuan · Siyuan · CVE-2026-82654
**Name of the Vulnerable Software and Affected Versions**
SiYuan versions prior to 3.8.1
**Description**
Improper escaping of block name, alias, and memo fields occurs within the hint, backlink, and breadcrumb rendering functions. This allows an attacker to inject HTML or script tags into a block's name, which are then executed when another user views documents that reference or display that block.
**Recommendations**
Update to version 3.8.1 or later.