PT-2026-57008 · Siyuan · Siyuan

CVE-2026-59833

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.1
Description SiYuan uses the Lute engine to render note and package content into HTML. A flaw in the sanitization process occurs because the dangerous javascript scheme block fails to validate the form action and SVG xlink:href attributes. This allows for stored cross-site scripting (XSS) within the document export-preview and Bazaar package README render paths, which can lead to the execution of operating system commands in the Electron desktop renderer.
Recommendations Update to version 3.7.1.

Exploit

Fix

RCE

Improper Encoding or Escaping of Output

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59833
GHSA-97XV-3V84-H358

Affected Products

Siyuan