OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-93923 (CVSS 8.6)

NVD · officialPublished Sep 19, 2026Risk 37/100EPSS 0.4%

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

CVSS
8.6
AV:NetworkAC:LowPR:NoneUI:Active

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source