PT-2026-83580 · Siyuan · Siyuan

·

CVE-2026-82654

·

Published

2026-08-30

·

Updated

2026-09-04

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.1
Description Improper escaping of block name, alias, and memo fields occurs within the hint, backlink, and breadcrumb rendering functions. This allows an attacker to inject HTML or script tags into a block's name, which are then executed when another user views documents that reference or display that block.
Recommendations Update to version 3.8.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82654
GHSA-HF87-QH3J-3P88

Affected Products

Siyuan