SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextIsolation disabled, attacker-controlled JavaScript executes with access to Node.js APIs. In practice, an attacker can import a crafted note into a synced workspace, wait for the victim to sync, and achieve code execution when the victim opens the note. This vulnerability is fixed in 3.6.4.
The table caption content is saved without proper escaping and then injected directly into the rendered HTML — creating a vulnerable stored XSS point. The SiYuan desktop client is based on Electron with nodeIntegration enabled and contextIsolation disabled, which causes embedded JavaScript to execute with full access to Node.js APIs. An attacker imports a crafted note into a shared workspace, and after synchronization by the victim, the malicious code executes automatically when the note is opened.
An attacker gains the ability to execute arbitrary code with the privileges of the SiYuan process on the victim's computer, which may lead to full system compromise, data theft, or malicious software installation.
SiYuan should be updated to version 3.6.4 or later, in which the vulnerability has been fixed. The vulnerability is identified in the official security advisory from the vendor available in the references.
B3Log SiYuan in versions prior to 3.6.4 — affects the desktop client (Electron) using note synchronization functionality.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HB3log Siyuan
APPB3Log< 3.6.4
Related vulnerabilities
B3Log SiYuan: XSS w diagramach Mermaid eskaluje do RCE w Electron
RCE w SiYuan poprzez nadmiernie permisywną politykę CORS
Stored XSS → RCE w B3Log SiYuan via złośliwy URL w Attribute View
Path Traversal w B3Log SiYuan — nieautoryzowane odczytywanie struktury plików
B3Log SiYuan — nieuprawniony odczyt treści dokumentów przez API