CVE-2026-93922
published 2026-09-19CVE-2026-93922: SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.54%
44.6th percentile
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | <= 3.8.4 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.8.4 Daily Note Picker Dialog cross site scripting
vuldb·2026-09-19·CVSS 8.8
CVE-2026-93922 [HIGH] siyuan-note SiYuan up to 3.8.4 Daily Note Picker Dialog cross site scripting
A vulnerability classified as problematic was found in siyuan-note SiYuan up to 3.8.4. This impacts an unknown function of the component Daily Note Picker Dialog. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-93922. The attack may be launched remotely. There is no exploit available.
GHSA
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer.
ghsa_unreviewed·2026-09-19
CVE-2026-93922 [HIGH] CWE-79 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer.
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuanhttps://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/mount.ts#L72https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/file.go#L2446-L2454https://github.com/siyuan-note/siyuan/security/advisories/GHSA-8c2m-33v9-vvqmhttps://www.vulncheck.com/advisories/siyuan-through-3.8.4-stored-xss-via-notebook-nameshttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-8c2m-33v9-vvqm
2026-09-19
Published