CVE-2026-100641: SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content

Published Sep 26, 2026
·
Updated

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication and administrator-role checks; this is an untrusted-content-to-privileged-renderer issue, not an authorization bypass.

Affected Software

1 affected component
SiYuan SiYuan<3.8.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.4

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
May 29, 58707
Event
via NVD·06:04 PM

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Administrators using the SiYuan desktop application are exposed when they open the card manager for a workspace that contains attacker-supplied flashcard content. Content may be introduced through sources such as contributions or imports.

2

What does an attacker need to do to exploit it?

The attacker needs to get crafted content into a stored flashcard block and convince an administrator to open the card manager. The vulnerable card-list rendering then inserts the content as HTML, allowing event-handler attributes to execute.

3

Is this an authentication or authorization bypass?

No. The affected /api/riff/getRiffCards endpoint remains protected by authentication and administrator-role checks; the issue is execution of untrusted stored content in a privileged renderer after an authorized administrator views it.

4

What can be done before updating?

Avoid opening the card manager for workspaces containing untrusted flashcard content, including content received through contributions or imports. Review such content before it is made available to administrators.

5

How can an organization assess whether it may be affected?

Check whether it runs a SiYuan version earlier than v3.8.4 and whether administrators use the card manager on workspaces that accept imported or contributor-supplied flashcard blocks. Crafted HTML such as an image element with an event-handler attribute is an indicator of malicious content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203