Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-93922: SiYuan up to 3.8.4 lets malicious notebook names run code

CVE-2026-93922 · published 10 days ago
Summary

The SiYuan note‑taking app (versions 3.8.4 and earlier) shows notebook names without cleaning them first. If an attacker creates a notebook with specially crafted HTML in its name, that code runs automatically when a user opens the Daily Note picker, giving the attacker the ability to run commands on the computer. Upgrade to the latest SiYuan version or remove any suspicious notebook names to protect your system.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
siyuan-note siyuan <= 3.8.4
Original advisory text
SiYuan through 3.8.4 Stored XSS via notebook names
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
Severity
8.6 High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published19 Sep 2026
Updated29 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-93922 · MITRE
Track software like this
Free during beta