CVE-2026-66394: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, enabling script execution in the application origin.
AI Analysis
Technical Summary
CVE-2026-66394 describes stored and reflected cross-site scripting vulnerabilities in SiYuan note-taking software prior to version 3.7.3. The issue arises from insufficient sanitization of SVG content, allowing authenticated attackers to embed malicious scripts within SVG elements (desc, style, noscript) that bypass the HTML parser-based cleaner. While these elements appear as raw text to the HTML parser, browsers interpret them as executable SVG content when served as image/svg+xml, leading to script execution within the application's origin. This can compromise the security of the application and its users.
Potential Impact
Successful exploitation allows authenticated attackers to execute arbitrary scripts in the context of the SiYuan application origin. This can lead to session hijacking, unauthorized actions, or data theft within the application. The vulnerability affects confidentiality, integrity, and availability as indicated by the high CVSS vector metrics.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided at this time. Until a patch is available, restrict authenticated user privileges to trusted users only and consider disabling SVG content rendering if possible.
CVE-2026-66394: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
Description
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, enabling script execution in the application origin.
CVSS v4.0
Score 9.3critical
Affected software
siyuan-note
siyuan
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-66394 describes stored and reflected cross-site scripting vulnerabilities in SiYuan note-taking software prior to version 3.7.3. The issue arises from insufficient sanitization of SVG content, allowing authenticated attackers to embed malicious scripts within SVG elements (desc, style, noscript) that bypass the HTML parser-based cleaner. While these elements appear as raw text to the HTML parser, browsers interpret them as executable SVG content when served as image/svg+xml, leading to script execution within the application's origin. This can compromise the security of the application and its users.
Potential Impact
Successful exploitation allows authenticated attackers to execute arbitrary scripts in the context of the SiYuan application origin. This can lead to session hijacking, unauthorized actions, or data theft within the application. The vulnerability affects confidentiality, integrity, and availability as indicated by the high CVSS vector metrics.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided at this time. Until a patch is available, restrict authenticated user privileges to trusted users only and consider disabling SVG content rendering if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-26T12:22:34.139Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6786039c2644c7f861a517
Added to database: 07/27/2026, 16:23:31 UTC
Last enriched: 07/30/2026, 00:51:36 UTC
Last updated: 09/10/2026, 20:02:52 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.