PT-2026-99310 · Siyuan · Siyuan

·

CVE-2026-100639

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description Insufficient HTML-escaping of the data-subtype attribute occurs when generating gutter-button markup from plain-text Markdown containing a Kramdown inline attribute list (IAL). The Lute renderer parses Kramdown IAL from text/plain input, allowing an attacker to use entity-encoded quotes in data-subtype to break out of the attribute value. This enables the injection of additional attributes, such as autofocus and onfocus. When the affected gutter control receives focus, the injected handler executes. In the Electron desktop application, where the main BrowserWindow enables Node integration and disables context isolation, this leads to remote code execution with renderer Node.js privileges.
Recommendations Update to version 3.8.4.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100639
GHSA-2CMM-9X9J-RVFF

Affected Products

Siyuan