CVE 9.4 CRITICAL

SiYuan – Remote Code Execution via Malicious Bazaar Package Metadata and README_CVE-2026-56397

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

Basic Information

ID CVE-2026-56397
Source VulnCheck
Published Jun 21, 2026 at 13:27

Affected Product

Vendor SiYuan
Product SiYuan
Affected Versions SiYuan SiYuan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.