PT-2026-99314 · Siyuan · Siyuan

·

CVE-2026-100643

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description Authenticated attackers can inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates because four stored Attribute View values in textarea elements are not properly escaped. This allows the execution of stored JavaScript when other users open affected database menus. In the Electron desktop app, if nodeIntegration is enabled, this can lead to command execution with SiYuan process privileges.
Recommendations Update SiYuan to version 3.8.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100643
GHSA-H3P6-C22R-FX2J

Affected Products

Siyuan