PT-2026-83575 · Siyuan · Siyuan

·

CVE-2026-82649

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SiYuan Windows installer versions 2.0.14 through 3.8.0
Description The NSIS installer contains an uncontrolled search path element issue where system executables, such as TASKKILL, are invoked by name instead of by an absolute path. The nsExec::Exec function resolves these calls using a search path that prioritizes the installer's launch directory over System32. An attacker can place a malicious executable with the same name in the launch directory to achieve local privilege escalation, as the binary executes with an elevated token during an all-users installation. This occurs within the preInit hook of electron-builder before the license page is shown.
Recommendations Update to version 3.8.1 or later.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82649
GHSA-9J65-967F-5RV3

Affected Products

Siyuan