PT-2026-51238 · Siyuan · Siyuan

0Xkakash1

·

Published

2026-06-21

·

Updated

2026-06-21

·

CVE-2026-56397

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.1
Description SiYuan fails to sanitize package metadata and README content within the Bazaar marketplace. This allows malicious authors to inject arbitrary HTML and JavaScript through the displayName, description, or README fields. Because the application is built on Electron with nodeIntegration enabled—a setting that allows JavaScript to access Node.js APIs—the injected scripts can escape the browser context to execute operating system commands, resulting in remote code execution on the device of any user browsing the marketplace.
Recommendations Update to version 3.6.1.

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56397

Affected Products

Siyuan