CVE-2026-82653
published 2026-08-30CVE-2026-82653: SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated…
PriorityP339high8.9CVSS 3.1
AVNACLPRLUIRSCCHIHAL
EPSS
0.22%
13.2th percentile
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.1 | 3.8.1 |
CVSS provenance
nvdv3.18.9HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.8.0 Bazaar confirmDialog Name cross site scripting
vuldb·2026-08-30·CVSS 8.9
CVE-2026-82653 [HIGH] siyuan-note SiYuan up to 3.8.0 Bazaar confirmDialog Name cross site scripting
A vulnerability marked as problematic has been reported in siyuan-note SiYuan up to 3.8.0. This affects the function confirmDialog of the component Bazaar. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is listed as CVE-2026-82653. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments.
ghsa_unreviewed·2026-08-30
CVE-2026-82653 [CRITICAL] CWE-79 SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments.
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-30
Published