Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-92986: SiYuan before 3.8.4 can run code via document titles
CVE-2026-92986 · published 1 day ago
Summary
The SiYuan note‑taking app lets a note's title be displayed without cleaning out special characters. An attacker who can change a title could insert code that runs on the user’s computer. Update SiYuan to version 3.8.4 or later to stop this behavior.
What to do
- Update siyuan-note siyuan to version 3.8.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siyuan-note | siyuan | < 3.8.4 |
Original advisory text
SiYuan before 3.8.4 Cross-Site Scripting via Document Title
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
References
- https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8... Patch
- https://github.com/siyuan-note/siyuan Product
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-c5h9-g2c6-fxjw Vendor Advisory
- https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134 Third Party Advisory
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-vi... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92986... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92986 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 8.8 (MITRE)
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published17 Sep 2026
Updated19 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta