Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100641— SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content

Quick assessment

Affected
siyuan-note siyuan
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SiYuan v3.8.4 之前版本存在一个漏洞:在将存储的闪卡块内容插入到卡片管理器列表标记之前,未对其执行 HTML 转义。通过 接口返回的块内容会被直接插入到 中的卡片项模板,并赋值给 。因此,类似 的内容会形成可执行的事件处理属性。 由于 SiYuan 桌面版(基于 Electron)的主窗口创建时启用了 并禁用了 ,当管理员打开包含攻击者提供的闪卡内容(例如通过贡献或导入引入)的工作区时,攻击者的脚本将在具有特权的渲染器进程中执行,从而导致在主机上任意代码执行。 该受影响端点仍然位于身份验证和管理员角色检

CVSS 8.0 · High EPSS 0.53% · P43
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100641

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content
Source: CVE Program / CVE List V5
Vulnerability Description
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication and administrator-role checks; this is an untrusted-content-to-privileged-renderer issue, not an authorization bypass.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
siyuan-note siyuan 0 ~ 3.8.4 -

II. Public POCs for CVE-2026-100641

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100641

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100641 (1)

Other References for CVE-2026-100641 (5)

Same Patch Batch · siyuan-note · 2026-09-26 · 14 CVEs total

CVE-2026-100639 8.8 HIGH SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL
CVE-2026-100646 8.1 HIGH SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header
CVE-2026-100645 8.0 HIGH SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban
CVE-2026-100643 8.0 HIGH SiYuan before v3.8.4 Stored XSS via Attribute View textarea
CVE-2026-100642 7.6 HIGH SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth
CVE-2026-100637 7.6 HIGH SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID
CVE-2026-100638 7.6 HIGH SiYuan before v3.8.4 Path Traversal via setNotebookIcon
CVE-2026-100636 7.6 HIGH SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder
CVE-2026-100644 7.5 HIGH SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath
CVE-2026-100633 6.5 MEDIUM SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations
CVE-2026-100635 5.9 MEDIUM SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie
CVE-2026-100634 4.7 MEDIUM SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows
CVE-2026-100640 4.7 MEDIUM SiYuan before v3.8.4 Clipboard Data Disclosure via IPC

IV. Related Vulnerabilities

V. Comments for CVE-2026-100641

No comments yet


Leave a comment