CVE-2026-100641
published 2026-09-26CVE-2026-100641: SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by…
PriorityP353high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.53%
43.0th percentile
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication and administrator-role checks; this is an untrusted-content-to-privileged-renderer issue, not an authorization bypass.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.4 | 3.8.4 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup.
ghsa_unreviewed·2026-09-26
CVE-2026-100641 [HIGH] CWE-79 SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup.
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication
VulDB
siyuan-note SiYuan up to 3.8.3 Card Manager viewCards.ts cross site scripting
vuldb·2026-09-26·CVSS 8.0
CVE-2026-100641 [HIGH] siyuan-note SiYuan up to 3.8.3 Card Manager viewCards.ts cross site scripting
A vulnerability was found in siyuan-note SiYuan up to 3.8.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/src/card/viewCards.ts of the component Card Manager. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-100641. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuan/commit/1ecb1c07de497ff03b585536fe5579291754d96bhttps://github.com/siyuan-note/siyuan/commit/41b14025b4ac4a8379d1200580344ca18ad152b7https://github.com/siyuan-note/siyuan/commit/48c354e7de130aaada9d7120125bbc768344fd3bhttps://github.com/siyuan-note/siyuan/commit/8641553a1f07374001902d3ce773285db1292b2dhttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-2mmf-4xwm-55rmhttps://www.vulncheck.com/advisories/siyuan-before-3.8.4-stored-xss-via-unescaped-flashcard-contenthttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-2mmf-4xwm-55rm
2026-09-26
Published