PT-2026-94358 · Siyuan · Siyuan

·

CVE-2026-92985

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description Improper escaping of bookmark labels imported from notebook files occurs during rendering in the dock tree. This allows attackers to create malicious .sy notebook files containing unescaped HTML within bookmark attributes. When processed, these attributes can execute scripts in the Electron renderer, which has access to child process, enabling remote command execution.
Recommendations Update SiYuan to version 3.8.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92985
GHSA-JHFC-9MCQ-8P8V

Affected Products

Siyuan