思源笔记(SiYuan)3.8.4 及之前版本在渲染大纲和书签面板的 HTML 时,未对标题样式属性进行转义,从而导致存储型跨站脚本(XSS)漏洞。攻击者可以通过提供精心构造的笔记本,或调用管理端点,注入恶意样式值;这些值会在 Electron 渲染进程中执行,并获得对系统的完全访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93922 | 8.8 HIGH | SiYuan through 3.8.4 Stored XSS via notebook names |
| CVE-2026-93591 | 7.6 HIGH | SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go |
| CVE-2026-93921 | 4.3 MEDIUM | SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint |
No comments yet