CVE-2026-82654
published 2026-08-30CVE-2026-82654: SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a…
PriorityP344high8.9CVSS 3.1
AVNACLPRLUIRSCCHIHAL
EPSS
0.22%
13.2th percentile
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.1 | 3.8.1 |
CVSS provenance
nvdv3.18.9HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions.
ghsa_unreviewed·2026-08-30
CVE-2026-82654 [CRITICAL] CWE-79 SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions.
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
VulDB
siyuan-note SiYuan up to 3.8.0 Rendering Hint/Backlink/Breadcrumb Rendering Functions block name/alias/memo cross site scripting
vuldb·2026-08-30·CVSS 8.9
CVE-2026-82654 [HIGH] siyuan-note SiYuan up to 3.8.0 Rendering Hint/Backlink/Breadcrumb Rendering Functions block name/alias/memo cross site scripting
A vulnerability identified as problematic has been detected in siyuan-note SiYuan up to 3.8.0. The affected element is the function Hint/Backlink/Breadcrumb Rendering Functions of the component Rendering. Performing a manipulation of the argument block name/alias/memo results in cross site scripting.
This vulnerability is identified as CVE-2026-82654. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-30
Published