Junglewise Threat Intelligence

SiYuan marketplace XSS leading to remote code execution

Severity: critical · CVSS 9.6 · Published 2026-06-21

Technologies: SiYuan, github.com/siyuan-note/siyuan/kernel (Go). Vendors: SiYuan, Go.

Executive brief

SiYuan is a popular desktop note-taking application that includes a built-in Bazaar marketplace for browsing and installing themes, plugins, and templates. The application fails to properly escape or sanitize package metadata (names, descriptions) and README files before displaying them to users. A malicious package author can inject JavaScript code that executes automatically when users browse the marketplace, allowing them to run arbitrary commands on the user's computer—including stealing files, installing malware, or creating backdoors—without the user installing or even clicking on the malicious package.

Technical details

This is a cross-site scripting (XSS) vulnerability affecting Electron-based rendering with dangerously permissive settings. Root causes: (1) package metadata in bazaar.ts:275-277 is injected into HTML template literals without escaping; (2) README rendering in package.go:635-645 uses Lute markdown parser without calling SetSanitize(true), allowing raw HTML passthrough; (3) frontend code at bazaar.ts:607 assigns untrusted README HTML directly via innerHTML. The vulnerable Electron configuration (nodeIntegration: true, contextIsolation: false) enables attackers to execute arbitrary OS commands via require('child_process').exec() in the renderer context. Exploitation requires only network access and a victim browsing the marketplace—no authentication or user interaction needed for metadata-based XSS (zero-click); README XSS requires one click. The patch (v3.6.1) adds HTML escaping for metadata and enables SetSanitize(true) for Lute-based README rendering.

Affected products

  • SiYuan SiYuan before 3.6.1

Timeline

  • 2026-03-14: disclosed: Original GHSA advisory GHSA-v3mg-9v85-fcm7 published
  • 2026-06-21: advisory: CVE-2026-56397 assigned; duplicate advisory GHSA-24r3-p3x6-cqvx published
  • 2026-06-21: patched: Patch released in v3.6.1
  • 2026-09-14: other: Duplicate advisory GHSA-24r3-p3x6-cqvx withdrawn

References

Related threats