PT-2026-51238 · Siyuan · Siyuan

·

CVE-2026-56397

·

Published

2026-03-16

·

Updated

2026-08-19

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.1
Description SiYuan fails to sanitize package metadata and README content within the Bazaar marketplace. This allows malicious authors to inject arbitrary HTML and JavaScript through the displayName, description, or README fields. Because the application is built on Electron with nodeIntegration enabled—a setting that allows JavaScript to access Node.js APIs—the injected scripts can escape the browser context to execute operating system commands, resulting in remote code execution on the device of any user browsing the marketplace.
Recommendations Update to version 3.6.1.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56397
GHSA-V3MG-9V85-FCM7
GO-2026-4720

Affected Products

Siyuan