Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-82654: SiYuan lets malicious scripts run from block names
CVE-2026-82654 · published 4 days ago
Summary
Older versions of SiYuan do not clean the text used for block names, aliases, and notes when showing hints, backlinks, or navigation paths. An attacker could insert HTML or script code into a block name, causing the code to run whenever another user views that block or related pages. Update to version 3.8.1 or later to stop this behavior.
What to do
- Update siyuan-note siyuan to version 3.8.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siyuan-note | siyuan | < 3.8.1 |
Original advisory text
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags ...
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
References
Severity
9.3
Critical
CVSS 3.1: 8.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta