PT-2026-64995 · Siyuan · Siyuan

·

CVE-2026-66394

·

Published

2026-07-27

·

Updated

2026-09-10

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.3
Description Stored and reflected cross-site scripting issues exist in SVG sanitization. Authenticated attackers can bypass the HTML parser-based cleaner by hiding script tags within desc, style, or noscript elements. While the HTML parser treats these elements as raw text, browsers interpret them as executable SVG content when served as image/svg+xml, allowing script execution within the application origin.
Recommendations Update to version 3.7.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66394
GHSA-99RQ-75J6-5J9F
GO-2026-6364

Affected Products

Siyuan