思源笔记(SiYuan)v3.8.2 之前的版本存在一个存储型跨站脚本(Stored XSS)漏洞,位于“搜索资源”(Search Assets)的结果列表中:资源文件名在未进行 HTML 转义的情况下被直接拼接(interpolated)到 HTML 中。经过身份验证的攻击者可以构造包含恶意标记的资源文件名,当受害者执行资源搜索时,这些恶意标记会在受害者的浏览器中执行 JavaScript 代码,从而允许攻击者发起同源 API 请求并操纵应用程序状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87815 | 8.7 HIGH | SiYuan before v3.8.2 Path Traversal via removeRiffDeck |
| CVE-2026-87807 | 7.5 HIGH | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock |
| CVE-2026-87814 | 7.3 HIGH | SiYuan before v3.8.2 Stored XSS via Asset Preview |
| CVE-2026-87811 | 7.3 HIGH | SiYuan before v3.8.2 Stored XSS via notebook template paths |
| CVE-2026-87812 | 6.8 MEDIUM | SiYuan before v3.8.2 Stored XSS via Bazaar iconURL |
| CVE-2026-87809 | 6.5 MEDIUM | Siyuan before v3.8.2 Information Disclosure via Export Preview |
| CVE-2026-87810 | 5.3 MEDIUM | Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock |
| CVE-2026-87808 | 4.9 MEDIUM | SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock |
No comments yet