PT-2026-52111 · Siyuan · Siyuan

CVE-2026-54158

·

Published

2026-06-24

·

Updated

2026-07-30

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.0
Description The attribute-view cell renderer genAVValueHTML fails to properly sanitize cell content in the text, url, phone, and mAsset branches. This allows an attacker with write access to a synced workspace to inject malicious payloads into cell values. When a victim opens the block-attribute panel, the payload breaks out of the surrounding tag to execute arbitrary JavaScript. On Electron desktop installations, where the renderer operates with nodeIntegration:true, this Cross-Site Scripting (XSS) can be escalated to Remote Code Execution (RCE) on the host machine via require('child process'). The issue persists because the kernel does not escape the data upon entry, and there is no equivalent protection to html.EscapeAttrVal for block IAL attributes in kernel/model/blockial.go:261.
Recommendations Update to version 3.7.0.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54158
GHSA-5XFX-XJ4H-5P7R
GO-2026-5957
OPENSUSE-SU-2026:21483-1

Affected Products

Siyuan