SiYuan 在 v3.8.2 之前版本中存在一个存储型跨站脚本(XSS)漏洞,位于搜索资产预览功能中。该功能在将索引化的资产内容插入 DOM 时,未对内容进行适当的转义处理,而是直接使用 进行插入。攻击者若能在工作区中放置特制的文本资产,则当受害者预览这些资产时,可以在 SiYuan 的源(origin)中执行 JavaScript 代码,从而发起已认证的 API 请求并操控工作区。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87815 | 8.7 HIGH | SiYuan before v3.8.2 Path Traversal via removeRiffDeck |
| CVE-2026-87807 | 7.5 HIGH | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock |
| CVE-2026-87811 | 7.3 HIGH | SiYuan before v3.8.2 Stored XSS via notebook template paths |
| CVE-2026-87813 | 7.3 HIGH | SiYuan before v3.8.2 Stored XSS via unescaped asset filenames |
| CVE-2026-87812 | 6.8 MEDIUM | SiYuan before v3.8.2 Stored XSS via Bazaar iconURL |
| CVE-2026-87809 | 6.5 MEDIUM | Siyuan before v3.8.2 Information Disclosure via Export Preview |
| CVE-2026-87810 | 5.3 MEDIUM | Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock |
| CVE-2026-87808 | 4.9 MEDIUM | SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock |
No comments yet