PT-2026-52111 · Siyuan · Siyuan
CVE-2026-54158
·
Published
2026-06-24
·
Updated
2026-07-30
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.0
Description
The attribute-view cell renderer
genAVValueHTML fails to properly sanitize cell content in the text, url, phone, and mAsset branches. This allows an attacker with write access to a synced workspace to inject malicious payloads into cell values. When a victim opens the block-attribute panel, the payload breaks out of the surrounding tag to execute arbitrary JavaScript. On Electron desktop installations, where the renderer operates with nodeIntegration:true, this Cross-Site Scripting (XSS) can be escalated to Remote Code Execution (RCE) on the host machine via require('child process'). The issue persists because the kernel does not escape the data upon entry, and there is no equivalent protection to html.EscapeAttrVal for block IAL attributes in kernel/model/blockial.go:261.Recommendations
Update to version 3.7.0.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siyuan