MajorCritical vulnerability
CVE-2026-93922 (CVSS 8.6)
NVD · officialPublished Sep 19, 2026Risk 37/100EPSS 0.5%
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.
Technical details
CVSS
8.6
AV:NetworkAC:LowPR:NoneUI:Active
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source