8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron client's permissive security configuration, an attacker can include a malicious <iframe> in a Bazaar package README that executes arbitrary commands on the victim's machine when the package details are viewed. No package installation is required. This vulnerability is fixed in 3.7.0.
AI Analysis
Arbitrary command execution via malicious iframe in Bazaar package README
Basic Information
ID
CVE-2026-54759
Source
GitHub_M
Published
Jun 24, 2026 at 21:21
Affected Product
Vendor
siyuan-note
Product
siyuan
Version
< 3.7.0
Affected Versions
siyuan-note siyuan < 3.7.0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
siyuan-note
Product
SiYuan
Version
< 3.7.0