PT-2026-51236 · Siyuan · Siyuan

·

CVE-2026-56395

·

Published

2026-03-16

·

Updated

2026-08-19

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.1
Description SiYuan fails to sanitize package metadata and README content within the Bazaar marketplace. This allows malicious authors to inject arbitrary HTML and JavaScript into the displayName, description, or README fields. Because the application is built on Electron with the nodeIntegration setting enabled, these Cross-Site Scripting (XSS) payloads can escape the browser context to execute operating system commands, leading to remote code execution on the device of any user browsing the marketplace.
Recommendations Update to version 3.6.1.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56395
GHSA-V3MG-9V85-FCM7
GO-2026-4720

Affected Products

Siyuan