Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-92986: SiYuan before 3.8.4 can run code via document titles

CVE-2026-92986 · published 1 day ago
Summary

The SiYuan note‑taking app lets a note's title be displayed without cleaning out special characters. An attacker who can change a title could insert code that runs on the user’s computer. Update SiYuan to version 3.8.4 or later to stop this behavior.

What to do
  • Update siyuan-note siyuan to version 3.8.4 or later.
Affected software
VendorProductAffected versions
siyuan-note siyuan < 3.8.4
Original advisory text
SiYuan before 3.8.4 Cross-Site Scripting via Document Title
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
Severity
9.9 Critical
CVSS 3.1: 8.8 (MITRE)
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published17 Sep 2026
Updated19 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-92986 · MITRE
Track software like this
Free during beta