CVE-2026-65606: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.
AI Analysis
Technical Summary
CVE-2026-65606 describes a cross-site scripting vulnerability in SiYuan note-taking software prior to version 3.7.2. The vulnerability arises in the siyuan:// protocol handler when a link to a non-installed plugin is processed. The application inserts the icon parameter from the link into the tab header using innerHTML without proper escaping, enabling injection of malicious HTML such as an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node.js require and execute arbitrary OS commands via require('child_process').execSync(...), significantly escalating the impact of the XSS.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands on the victim's machine due to the combination of XSS and nodeIntegration:true in the SiYuan Desktop renderer. This leads to a critical security risk including full system compromise. The vulnerability requires user interaction (UI:P) but no privileges or authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid clicking untrusted siyuan:// links referencing non-installed plugins. Monitor vendor channels for updates and apply patches promptly once released.
CVE-2026-65606: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
Description
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.
CVSS v4.0
Score 9.4critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65606 describes a cross-site scripting vulnerability in SiYuan note-taking software prior to version 3.7.2. The vulnerability arises in the siyuan:// protocol handler when a link to a non-installed plugin is processed. The application inserts the icon parameter from the link into the tab header using innerHTML without proper escaping, enabling injection of malicious HTML such as an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node.js require and execute arbitrary OS commands via require('child_process').execSync(...), significantly escalating the impact of the XSS.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands on the victim's machine due to the combination of XSS and nodeIntegration:true in the SiYuan Desktop renderer. This leads to a critical security risk including full system compromise. The vulnerability requires user interaction (UI:P) but no privileges or authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid clicking untrusted siyuan:// links referencing non-installed plugins. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-22T10:48:36.000Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6207979c2644c7f80b64a2
Added to database: 07/23/2026, 12:22:47 UTC
Last enriched: 07/30/2026, 22:26:35 UTC
Last updated: 09/03/2026, 22:52:13 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.