SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as are skipped by that check, a payload like is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution.
CVE-2026-65605
Score 9.6 from GitHub Security Advisory (severity: CRITICAL) published 2026-07-23. the CNA's CVSS baseline 9.6; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.6
- EG Score
- 9.6(medium)
- EG Risk
- 59(Track*)EG Risk 59/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity96% × 45%Exploitation40% × 40%Automatability0% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 1%
- EPSS %ILE
- 53%
- KEV
- Not listed
Published
July 23, 2026
Last Modified
July 28, 2026
Advisory Details (3)
Auto-updated Aug 23, 2026SiYuan before v3.7.2 Stored XSS to RCE via Attribute View | Advisories | VulnCheck
https://www.vulncheck.com/advisories/siyuan-before-stored-xss-to-rce-via-attribute-viewcommit 41f2861c8757 (siyuan-note/siyuan)
Fix landed in siyuan-note/siyuan commit 41f2861c8757 — awaiting tagged release
https://github.com/siyuan-note/siyuan/commit/41f2861c87575ff5ac4b50a0520b1a4fe55b4a70Attribute View cell values: stored XSS to RCE (incomplete HTML escaping in renderCell) · Advisory · siyuan-note/siyuan · GitHub
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pw5c-qhf3-jhwhVendor Advisories for CVE-2026-65605(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 39× in last 7d / 208× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 256 total refreshes for this CVE.
- 2026-08-30 04:57 UTCEG score recompute
- 2026-08-30 04:57 UTCGHSA enrichment
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-30 00:35 UTCEG score recompute
- 2026-08-30 00:35 UTCGHSA enrichment
- 2026-08-28 21:42 UTCEPSS rescore
- 2026-08-28 01:30 UTCGHSA enrichment
- 2026-08-27 21:08 UTCGHSA enrichment
- 2026-08-27 14:46 UTCEG score recompute
- 2026-08-27 14:46 UTCGHSA enrichment
- 2026-08-27 10:11 UTCGHSA enrichment
- 2026-08-27 04:45 UTCGHSA enrichment
- 2026-08-27 00:17 UTCGHSA enrichment
- 2026-08-26 19:55 UTCGHSA enrichment
- 2026-08-26 15:10 UTCEG score recompute
- 2026-08-26 15:10 UTCGHSA enrichment
- 2026-08-26 14:47 UTCEPSS rescore
- 2026-08-26 10:41 UTCGHSA enrichment
- 2026-08-26 05:40 UTCGHSA enrichment
- 2026-08-26 01:11 UTCGHSA enrichment
- 2026-08-25 20:47 UTCGHSA enrichment
- 2026-08-25 16:21 UTCEG score recompute
- 2026-08-25 16:21 UTCGHSA enrichment
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 12:00 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-08-25 07:39 UTCGHSA enrichment
- 2026-08-25 03:17 UTCGHSA enrichment
- 2026-08-24 22:56 UTCGHSA enrichment
- 2026-08-24 18:35 UTCEG score recompute
- 2026-08-24 18:35 UTCGHSA enrichment
- 2026-08-24 14:13 UTCGHSA enrichment
- 2026-08-24 09:53 UTCEG score recompute
- 2026-08-24 09:53 UTCGHSA enrichment
- 2026-08-24 05:32 UTCGHSA enrichment
- 2026-08-24 01:11 UTCGHSA enrichment
- 2026-08-23 20:50 UTCGHSA enrichment
- 2026-08-23 16:29 UTCGHSA enrichment
- 2026-08-23 12:08 UTCGHSA enrichment
- 2026-08-23 07:47 UTCGHSA enrichment
- 2026-08-23 03:27 UTCEG score recompute
- 2026-08-23 03:27 UTCGHSA enrichment
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 23:06 UTCGHSA enrichment
- 2026-08-22 18:45 UTCGHSA enrichment
- 2026-08-22 14:24 UTCEG score recompute
- 2026-08-22 14:24 UTCGHSA enrichment
- 2026-08-22 09:59 UTCGHSA enrichment
- 2026-08-22 05:38 UTCGHSA enrichment
- 2026-08-22 01:17 UTCEG score recompute
- 2026-08-22 01:17 UTCGHSA enrichment
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 20:56 UTCGHSA enrichment
- 2026-08-21 16:35 UTCGHSA enrichment
- 2026-08-21 12:14 UTCGHSA enrichment
- 2026-08-21 07:53 UTCGHSA enrichment
- 2026-08-21 03:32 UTCGHSA enrichment
- 2026-08-20 23:11 UTCEG score recompute
- 2026-08-20 23:11 UTCGHSA enrichment
- 2026-08-20 22:56 UTCEPSS rescore
- 2026-08-20 18:50 UTCGHSA enrichment
- 2026-08-20 14:29 UTCGHSA enrichment
- 2026-08-20 09:38 UTCGHSA enrichment
- 2026-08-20 05:18 UTCGHSA enrichment
- 2026-08-20 00:57 UTCGHSA enrichment
- 2026-08-19 20:34 UTCEG score recompute
- 2026-08-19 20:34 UTCGHSA enrichment
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 12:29 UTCGHSA enrichment
- 2026-08-19 08:03 UTCGHSA enrichment
- 2026-08-19 03:42 UTCGHSA enrichment
- 2026-08-18 23:21 UTCGHSA enrichment
- 2026-08-18 19:00 UTCEG score recompute
- 2026-08-18 19:00 UTCGHSA enrichment
- 2026-08-18 13:48 UTCEPSS rescore
- 2026-08-18 10:10 UTCGHSA enrichment
- 2026-08-18 05:47 UTCGHSA enrichment
- 2026-08-18 01:27 UTCGHSA enrichment
- 2026-08-17 20:24 UTCGHSA enrichment
- 2026-08-17 15:38 UTCEG score recompute
- 2026-08-17 15:38 UTCGHSA enrichment
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 11:17 UTCGHSA enrichment
- 2026-08-17 06:56 UTCGHSA enrichment
- 2026-08-17 02:36 UTCGHSA enrichment
- 2026-08-16 22:15 UTCGHSA enrichment
- 2026-08-16 17:54 UTCEG score recompute
- 2026-08-16 17:54 UTCGHSA enrichment
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 13:33 UTCGHSA enrichment
- 2026-08-16 09:11 UTCGHSA enrichment
- 2026-08-16 04:51 UTCEG score recompute
- 2026-08-16 04:51 UTCGHSA enrichment
- 2026-08-16 00:30 UTCGHSA enrichment
- 2026-08-15 20:09 UTCGHSA enrichment
- 2026-08-15 15:48 UTCGHSA enrichment
- 2026-08-15 11:27 UTCGHSA enrichment
- 2026-08-15 07:06 UTCGHSA enrichment
- 2026-08-15 01:42 UTCEG score recompute
- 2026-08-15 01:42 UTCGHSA enrichment
- 2026-08-15 01:30 UTCEPSS rescore
Frequently asked(5)
What is CVE-2026-65605?
When was CVE-2026-65605 disclosed?
Is CVE-2026-65605 actively exploited?
What is the CVSS score of CVE-2026-65605?
How do I remediate CVE-2026-65605?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-65605
Is Your Infrastructure Affected by CVE-2026-65605?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.