CVE-2026-100645: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
AI Analysis
Technical Summary
CVE-2026-100645 is a stored cross-site scripting vulnerability affecting SiYuan note-taking software versions from 3.7.0 to before 3.8.4. The issue is due to improper neutralization of input during web page generation, specifically in the gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. This allows an attacker to inject malicious JavaScript. In the context of the Electron desktop app with nodeIntegration enabled, the injected script can invoke Node.js child_process APIs, enabling arbitrary command execution with the privileges of the user running the app.
Potential Impact
Successful exploitation can lead to arbitrary command execution on the user's system with their privileges, due to JavaScript injection combined with Node.js API access in the Electron app. This elevates the risk beyond typical XSS attacks, potentially allowing full compromise of the affected host.
Mitigation Recommendations
A fixed version is available starting from SiYuan 3.8.4. Users should upgrade to version 3.8.4 or later to remediate this vulnerability. No additional mitigation steps are indicated in the vendor advisory.
CVE-2026-100645: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
Description
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
CVSS v4.0
Score 8.6high
Affected software
siyuan-note
siyuan
pkg:github/siyuan-note/siyuanRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100645 is a stored cross-site scripting vulnerability affecting SiYuan note-taking software versions from 3.7.0 to before 3.8.4. The issue is due to improper neutralization of input during web page generation, specifically in the gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. This allows an attacker to inject malicious JavaScript. In the context of the Electron desktop app with nodeIntegration enabled, the injected script can invoke Node.js child_process APIs, enabling arbitrary command execution with the privileges of the user running the app.
Potential Impact
Successful exploitation can lead to arbitrary command execution on the user's system with their privileges, due to JavaScript injection combined with Node.js API access in the Electron app. This elevates the risk beyond typical XSS attacks, potentially allowing full compromise of the affected host.
Mitigation Recommendations
A fixed version is available starting from SiYuan 3.8.4. Users should upgrade to version 3.8.4 or later to remediate this vulnerability. No additional mitigation steps are indicated in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:32:35.659Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a7f7a7c5410652fd2d
Added to database: 09/26/2026, 13:33:27 UTC
Last enriched: 09/26/2026, 14:03:12 UTC
Last updated: 09/27/2026, 01:57:11 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.