Siyuan · Siyuan · CVE-2026-100643
**Name of the Vulnerable Software and Affected Versions**
SiYuan versions prior to 3.8.4
**Description**
Authenticated attackers can inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates because four stored Attribute View values in textarea elements are not properly escaped. This allows the execution of stored JavaScript when other users open affected database menus. In the Electron desktop app, if `nodeIntegration` is enabled, this can lead to command execution with SiYuan process privileges.
**Recommendations**
Update SiYuan to version 3.8.4 or later.