PT-2026-31031 · Electron+1 · Electron+1
Ngocnn97
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-39846
CVSS v3.1
9.0
Critical
| AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.6.4
Description
SiYuan, a personal knowledge management system, is susceptible to remote code execution in the Electron desktop client prior to version 3.6.4. This occurs because table caption content is stored and rendered in HTML without proper escaping, creating a stored cross-site scripting (XSS) vulnerability. The desktop renderer's configuration, with nodeIntegration enabled and contextIsolation disabled, allows attacker-controlled JavaScript to execute with full access to Node.js APIs. An attacker can exploit this by importing a crafted note into a synced workspace, which then executes code on the victim's machine when the note is opened.
Recommendations
Update to version 3.6.4 or later.
Fix
RCE
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Electron
Siyuan