PT-2026-33376 · Siyuan · Siyuan

Published

2026-03-14

·

Updated

2026-04-17

·

CVE-2026-40922

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions 3.6.1 through 3.6.3
Description An issue exists in the bazaar README rendering where the Lute HTML sanitizer fails to block iframe tags and does not effectively filter srcdoc attributes containing raw HTML. A malicious bazaar package author can include an iframe with a srcdoc attribute containing embedded scripts in their README. When users view the package in the marketplace UI, the payload executes in the Electron context with full application privileges, allowing arbitrary code execution on the user's machine.
Recommendations Update to version 3.6.4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07547
CVE-2026-40922
GHSA-8Q5W-MMXF-48JG

Affected Products

Siyuan