Junglewise Threat Intelligence

CVE-2026-54759: SiYuan remote code execution via Lute HTML sanitizer bypass in Bazaar README

CVE-2026-54759 · Severity: info · CVSS 8.7 · Published 2026-06-24

Technologies: SiYuan Note SiYuan, SiYuan. Vendors: SiYuan Note, SiYuan.

Executive brief

SiYuan is an open-source personal knowledge management system. A security flaw in how the application displays package descriptions allows attackers to run malicious code on a user's computer. By simply viewing the details of a malicious package in the built-in marketplace, an attacker could steal private notes, access sensitive files, or take full control of the victim's system. No installation of the malicious package is required for the attack to succeed.

Technical details

A remote code execution (RCE) vulnerability exists in SiYuan due to a failure in the Lute HTML sanitizer to block <iframe> elements, combined with highly permissive Electron security settings (nodeIntegration: true, contextIsolation: false, and webSecurity: false). An attacker can craft a malicious Bazaar package README containing a hidden iframe that points to an external exploit script. Because webSecurity is disabled, the external script can perform authenticated cross-origin POST requests to the SiYuan API to write a payload to the local filesystem. This payload is then loaded into a same-origin iframe where it can access Node.js primitives to execute arbitrary system commands. This issue is distinct from previous sanitizer bypasses as it leverages the lack of origin isolation rather than specific attribute filtering. The vulnerability is patched in version 3.7.0.

Affected products

  • siyuan-note SiYuan < 3.7.0

Timeline

  • 2026-06-03: advisory: GitHub advisory published
  • 2026-06-24: disclosed: CVE published to NVD
  • 2026-06-24: patched: Fixed in version 3.7.0

References

Related threats