Junglewise Threat Intelligence

CVE-2026-44586: SiYuan Bazaar marketplace stored XSS and remote code execution

CVE-2026-44586 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a personal knowledge management system and note-taking application. A security flaw in its built-in marketplace allows malicious package authors to embed hidden code within their profile information. If a user simply browses the marketplace or views a malicious package's details, the attacker can gain full control over the user's computer, potentially leading to data theft, file deletion, or the installation of malware.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the SiYuan Bazaar marketplace due to improper neutralization of the 'author' metadata field. The application renders this field using 'innerHTML' without escaping, allowing an attacker to submit a malicious package to the public bazaar feed containing a JavaScript payload. In the Electron-based desktop application, because 'nodeIntegration' is enabled and 'contextIsolation' is disabled, the injected script can access Node.js APIs. This allows for arbitrary command execution on the host system when a user browses the marketplace (v3.6.4+) or views the package details (v2.1.12+). The issue is resolved in version 3.7.0.

Affected products

  • SiYuan SiYuan desktop app >= 2.1.12, < 3.7.0

Timeline

  • 2026-05-02: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD
  • 2026-05-14: patched: Vulnerability fixed in version 3.7.0

References

Related threats