Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-92985: SiYuan before 3.8.4 lets malicious notebook files run code
CVE-2026-92985 · published 11 days ago
Summary
Older versions of SiYuan do not properly clean up the text used for bookmark labels when a notebook file is opened. A specially crafted notebook can contain hidden code that runs on the computer, potentially allowing an attacker to execute commands. Upgrade SiYuan to version 3.8.4 or newer to stop this risk.
What to do
- Update siyuan-note siyuan to version 3.8.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siyuan-note | siyuan | < 3.8.4 |
Original advisory text
SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels
SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.
References
- https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8...
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jhfc-9mcq-8p8v
- https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-vi...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92985... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92985 Vendor Advisory
Severity
8.6
High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published17 Sep 2026
Updated29 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta