Executive brief
SiYuan is an open-source knowledge workspace application that runs on desktop systems. The application fails to properly escape heading style attributes when rendering outline and bookmark content in HTML, allowing attackers to inject malicious scripts that execute with full system access in the Electron renderer. An attacker can exploit this by supplying crafted notebooks or calling administrative endpoints to inject malicious styles that perform arbitrary actions on the affected system.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the rendering of heading style attributes within the outline and bookmark dock HTML components. The attack vector requires network access and the ability to supply crafted notebooks or call administrative endpoints. An attacker exploiting this vulnerability gains code execution within the Electron renderer process with full system access, representing a critical privilege escalation in a desktop application context.
Affected products
- SiYuan SiYuan through 3.8.4
Timeline
- 2026-09-19: disclosed