This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-56395 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
This record is a duplicate; use CVE-2026-56397 instead.
CVE-2026-56395 Blast Radius
✕ WITHDRAWN — HISTORICAL DATASiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arb…