CRITICAL🇵🇱 Wersja polska

CVE-2026-39846

CVSS 9.0v3.1pub. 2026-04-07upd. 2026-07-20

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextIsolation disabled, attacker-controlled JavaScript executes with access to Node.js APIs. In practice, an attacker can import a crafted note into a synced workspace, wait for the victim to sync, and achieve code execution when the victim opens the note. This vulnerability is fixed in 3.6.4.

🤖 AI Analysis
How it works

The table caption content is saved without proper escaping and then injected directly into the rendered HTML — creating a vulnerable stored XSS point. The SiYuan desktop client is based on Electron with nodeIntegration enabled and contextIsolation disabled, which causes embedded JavaScript to execute with full access to Node.js APIs. An attacker imports a crafted note into a shared workspace, and after synchronization by the victim, the malicious code executes automatically when the note is opened.

Impact

An attacker gains the ability to execute arbitrary code with the privileges of the SiYuan process on the victim's computer, which may lead to full system compromise, data theft, or malicious software installation.

Mitigation & patch

SiYuan should be updated to version 3.6.4 or later, in which the vulnerability has been fixed. The vulnerability is identified in the official security advisory from the vendor available in the references.

Who is affected

B3Log SiYuan in versions prior to 3.6.4 — affects the desktop client (Electron) using note synchronization functionality.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • B3log Siyuan

    APP
    B3Log
    < 3.6.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2026-40322CRITICAL9.0PL ✓same product

B3Log SiYuan: XSS w diagramach Mermaid eskaluje do RCE w Electron

CVE-2026-34449CRITICAL9.6PL ✓same product

RCE w SiYuan poprzez nadmiernie permisywną politykę CORS

CVE-2026-34448CRITICAL9.0PL ✓same product

Stored XSS → RCE w B3Log SiYuan via złośliwy URL w Attribute View

CVE-2026-33670CRITICAL9.8PL ✓same product

Path Traversal w B3Log SiYuan — nieautoryzowane odczytywanie struktury plików

CVE-2026-33669CRITICAL9.8PL ✓same product

B3Log SiYuan — nieuprawniony odczyt treści dokumentów przez API