CVE-2026-100643: SiYuan before v3.8.4 Stored XSS via Attribute View textarea
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.8.4
Event History
Frequently Asked Questions
Who is exposed to exploitation?
SiYuan deployments running versions before v3.8.4 are affected. Exploitation requires an authenticated attacker with the ability to modify Attribute View field descriptions, template sources, select option descriptions, or footer calculation templates, and a user must open an affected database menu.
What is the impact in the Electron desktop application?
When the Electron desktop app has nodeIntegration enabled, the stored JavaScript can lead to command execution with the privileges of the SiYuan process. Otherwise, the described impact is execution of stored JavaScript when another user opens the affected database menu.