MajorCritical vulnerability
CVE-2026-93923 (CVSS 8.6)
NVD · officialPublished Sep 19, 2026Risk 37/100EPSS 0.4%
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.
Technical details
CVSS
8.6
AV:NetworkAC:LowPR:NoneUI:Active
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source