CVE-2026-100643
published 2026-09-26CVE-2026-100643: SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject…
PriorityP345high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.42%
34.1th percentile
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | >= 2.10.8 < 3.8.4 | 3.8.4 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.8.3 Attribute View cross site scripting
vuldb·2026-09-26·CVSS 8.0
CVE-2026-100643 [HIGH] siyuan-note SiYuan up to 3.8.3 Attribute View cross site scripting
A vulnerability identified as problematic has been detected in siyuan-note SiYuan up to 3.8.3. This impacts an unknown function of the component Attribute View. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-100643. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, tem
ghsa_unreviewed·2026-09-26
CVE-2026-100643 [HIGH] CWE-79 SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, tem
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-26
Published