GHSA-qvp6-cjg5-8753HighCVSS 8.8

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark...

Published
September 19, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

🔗 References (8)