Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-82654: SiYuan lets malicious scripts run from block names

CVE-2026-82654 · published 4 days ago
Summary

Older versions of SiYuan do not clean the text used for block names, aliases, and notes when showing hints, backlinks, or navigation paths. An attacker could insert HTML or script code into a block name, causing the code to run whenever another user views that block or related pages. Update to version 3.8.1 or later to stop this behavior.

What to do
  • Update siyuan-note siyuan to version 3.8.1 or later.
Affected software
VendorProductAffected versions
siyuan-note siyuan < 3.8.1
Original advisory text
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags ...
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
Severity
9.3 Critical
CVSS 3.1: 8.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Sources
CVE-2026-82654 · MITRE
Monitor software like this
Free during beta