GHSA-hqj9-5q65-f4g9HighCVSS 8.8

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.

🔗 References (7)