PT-2026-99314 · Siyuan · Siyuan
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
Authenticated attackers can inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates because four stored Attribute View values in textarea elements are not properly escaped. This allows the execution of stored JavaScript when other users open affected database menus. In the Electron desktop app, if
nodeIntegration is enabled, this can lead to command execution with SiYuan process privileges.Recommendations
Update SiYuan to version 3.8.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan