PT-2026-29400 · Siyuan · Siyuan

Ngocnn97

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34585

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.2
Description SiYuan is a personal knowledge management system. A crafted block attribute value can bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, package it as a .sy.zip, and have the victim import it through the Import .sy.zip workflow. Once the note is opened, the malicious attribute breaks out of its original HTML context and injects an event handler, resulting in stored cross-site scripting (XSS). In the Electron desktop client, this XSS can lead to remote code execution because injected JavaScript runs with access to Node/Electron APIs. The issue involves manipulating block attributes and exploiting the interaction between HTML entities and special characters.
Recommendations Update to version 3.6.2.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-34585
GHSA-FF66-236V-P4FG

Affected Products

Siyuan