Junglewise Threat Intelligence

CVE-2026-82649: SiYuan Windows installer uncontrolled search path privilege escalation

CVE-2026-82649 · Severity: info · CVSS 7 · Published 2026-08-30

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a popular note-taking and knowledge management application. The Windows installer in versions 2.0.14 through 3.8.0 fails to use absolute paths when invoking system tools like TASKKILL, allowing an attacker to plant a malicious executable in the same directory and have it execute with administrator privileges during installation. This can lead to complete system compromise if the installer is run with elevated (all-users) privileges.

Technical details

The vulnerability is an uncontrolled search path element (CWE-427) in the NSIS-based Windows installer. The installer's preInit hook calls TASKKILL and other system utilities by name rather than absolute path; NSIS nsExec::Exec resolves these using a search path that includes the installer's launch directory ahead of System32. An attacker can place a malicious executable named TASKKILL.exe in the same directory as the installer, and it will execute before the license agreement is displayed—no user interaction beyond launching the installer is required. When the installer is run with all-users (elevated) privileges, the malicious binary executes with system-level privileges. The vulnerability affects versions 2.0.14 through 3.8.0 and is patched in version 3.8.1 by prefixing system utility calls with absolute paths.

Affected products

  • SiYuan SiYuan 2.0.14 through 3.8.0

Timeline

  • 2026-08-16: disclosed: GHSA-9j65-967f-5rv3 published
  • 2026-08-30: disclosed: CVE-2026-82649 published in NVD
  • 2026-08-30: patched: Fixed in version 3.8.1

References

Related threats