PT-2026-57008 · Siyuan · Siyuan
CVE-2026-59833
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.1
Description
SiYuan uses the Lute engine to render note and package content into HTML. A flaw in the sanitization process occurs because the dangerous javascript scheme block fails to validate the
form action and SVG xlink:href attributes. This allows for stored cross-site scripting (XSS) within the document export-preview and Bazaar package README render paths, which can lead to the execution of operating system commands in the Electron desktop renderer.Recommendations
Update to version 3.7.1.
Exploit
Fix
RCE
Improper Encoding or Escaping of Output
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siyuan