Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-93922: SiYuan up to 3.8.4 lets malicious notebook names run code
CVE-2026-93922 · published 10 days ago
Summary
The SiYuan note‑taking app (versions 3.8.4 and earlier) shows notebook names without cleaning them first. If an attacker creates a notebook with specially crafted HTML in its name, that code runs automatically when a user opens the Daily Note picker, giving the attacker the ability to run commands on the computer. Upgrade to the latest SiYuan version or remove any suspicious notebook names to protect your system.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siyuan-note | siyuan | <= 3.8.4 |
Original advisory text
SiYuan through 3.8.4 Stored XSS via notebook names
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93922... Vendor Advisory
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-8c2m-33v9-vvqm
- https://nvd.nist.gov/vuln/detail/CVE-2026-93922 Vendor Advisory
- https://pkg.go.dev URL
- https://www.vulncheck.com/advisories/siyuan-through-3.8.4-stored-xss-via-noteboo...
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/mount.ts#L72
- https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/file.go#L2446-L24...
Severity
8.6
High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published19 Sep 2026
Updated29 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta