SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-56395 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This record is a duplicate; use CVE-2026-56397 instead.
CVE-2026-56395
- CVSS v3
- 9.6
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- —Not applicable: this CVE ID was withdrawn
Published
June 21, 2026
Last Modified
June 22, 2026
Advisory Details (2)
Auto-updated Oct 7, 2026Remote Code Execution via Malicious Bazaar Package — Marketplace XSS · Advisory · siyuan-note/siyuan · GitHub
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-v3mg-9v85-fcm7SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README | Advisories | VulnCheck
https://www.vulncheck.com/advisories/siyuan-remote-code-execution-via-malicious-bazaar-package-metadata-and-readmeVendor Advisories for CVE-2026-56395(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(2 across 1 ecosystem)
Go(2)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| github.com/siyuan-note/siyuan/kernel | — |
| — |
| siyuan | — |
| — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 0× in last 7d / 13× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 429 total refreshes for this CVE.
- 2026-10-03 13:39 UTCOSV refresh
- 2026-09-30 04:29 UTCEG score recompute▼ 9.60
- 2026-09-17 19:31 UTCEPSS rescore
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-16 05:15 UTCEPSS rescore
- 2026-09-15 03:11 UTCEPSS rescore
- 2026-09-14 06:10 UTCGHSA enrichment
- 2026-09-14 02:10 UTCEG score recompute
- 2026-09-14 02:10 UTCGHSA enrichment
- 2026-09-13 16:47 UTCEPSS rescore
- 2026-09-13 12:52 UTCEG score recompute
- 2026-09-13 12:52 UTCGHSA enrichment
- 2026-09-11 14:53 UTCEPSS rescore
- 2026-09-10 09:35 UTCEPSS rescore
- 2026-09-08 22:01 UTCEPSS rescore
- 2026-09-07 16:01 UTCEPSS rescore
- 2026-09-06 13:47 UTCEPSS rescore
- 2026-09-04 05:07 UTCEPSS rescore
- 2026-09-02 14:12 UTCEPSS rescore
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-08-31 00:41 UTCGHSA enrichment
- 2026-08-30 20:41 UTCEG score recompute
- 2026-08-30 20:41 UTCGHSA enrichment
- 2026-08-30 19:17 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-28 21:42 UTCEPSS rescore
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 06:16 UTCGHSA enrichment
- 2026-08-25 02:16 UTCGHSA enrichment
- 2026-08-24 22:15 UTCEG score recompute
- 2026-08-24 22:15 UTCGHSA enrichment
- 2026-08-24 13:57 UTCEG score recompute
- 2026-08-24 13:57 UTCGHSA enrichment
- 2026-08-24 04:59 UTCGHSA enrichment
- 2026-08-23 23:57 UTCGHSA enrichment
- 2026-08-23 19:57 UTCGHSA enrichment
- 2026-08-23 15:57 UTCGHSA enrichment
- 2026-08-23 11:57 UTCGHSA enrichment
- 2026-08-23 07:54 UTCGHSA enrichment
- 2026-08-23 03:33 UTCEG score recompute
- 2026-08-23 03:33 UTCGHSA enrichment
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 22:54 UTCEG score recompute
- 2026-08-22 22:54 UTCGHSA enrichment
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 22:22 UTCGHSA enrichment
- 2026-08-21 18:14 UTCGHSA enrichment
- 2026-08-21 14:14 UTCGHSA enrichment
- 2026-08-21 09:26 UTCGHSA enrichment
- 2026-08-21 05:23 UTCGHSA enrichment
- 2026-08-21 00:25 UTCEG score recompute
- 2026-08-21 00:25 UTCGHSA enrichment
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-20 20:24 UTCGHSA enrichment
- 2026-08-20 16:24 UTCGHSA enrichment
- 2026-08-20 12:23 UTCGHSA enrichment
- 2026-08-20 07:53 UTCEG score recompute
- 2026-08-20 07:53 UTCGHSA enrichment
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 15:03 UTCGHSA enrichment
- 2026-08-19 11:01 UTCGHSA enrichment
- 2026-08-19 05:47 UTCEG score recompute
- 2026-08-19 05:47 UTCGHSA enrichment
- 2026-08-18 13:48 UTCEPSS rescore
- 2026-08-17 17:07 UTCEG score recompute
- 2026-08-17 17:06 UTCGHSA enrichment
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 13:04 UTCGHSA enrichment
- 2026-08-17 09:04 UTCGHSA enrichment
- 2026-08-17 05:05 UTCGHSA enrichment
- 2026-08-17 01:05 UTCGHSA enrichment
- 2026-08-16 21:05 UTCGHSA enrichment
- 2026-08-16 17:04 UTCEG score recompute
- 2026-08-16 17:04 UTCGHSA enrichment
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 13:04 UTCGHSA enrichment
- 2026-08-16 09:04 UTCGHSA enrichment
- 2026-08-16 05:04 UTCEG score recompute
- 2026-08-16 05:04 UTCGHSA enrichment
- 2026-08-16 02:14 UTCEPSS rescore
- 2026-08-16 01:04 UTCGHSA enrichment
- 2026-08-15 21:04 UTCGHSA enrichment
- 2026-08-15 17:04 UTCGHSA enrichment
- 2026-08-15 13:02 UTCGHSA enrichment
- 2026-08-15 08:49 UTCGHSA enrichment
- 2026-08-15 02:46 UTCEG score recompute
- 2026-08-15 02:46 UTCGHSA enrichment
- 2026-08-15 01:30 UTCEPSS rescore
- 2026-08-14 22:44 UTCGHSA enrichment
- 2026-08-14 18:44 UTCGHSA enrichment
- 2026-08-14 14:44 UTCGHSA enrichment
- 2026-08-14 10:44 UTCGHSA enrichment
- 2026-08-14 06:44 UTCGHSA enrichment
- 2026-08-14 02:44 UTCGHSA enrichment
- 2026-08-13 22:44 UTCEG score recompute
- 2026-08-13 22:44 UTCGHSA enrichment
- 2026-08-13 22:00 UTCEPSS rescore
Related CVEs(same product + same CWE)
Same product
10 shownGo:siyuan · Go:github.com/siyuan-note/siyuan/kernel
Frequently asked(4)
What is CVE-2026-56395?
When was CVE-2026-56395 disclosed?
What is the CVSS score of CVE-2026-56395?
How do I remediate CVE-2026-56395?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-56395
Is Your Infrastructure Affected by CVE-2026-56395?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.