GHSA-5x6r-p3h7-38vjCriticalCVSS 8.9

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint,...

Published
August 30, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.

🔗 References (4)