CVE-2026-23852: SiYuan vulnerable to Stored XSS / RCE via `setBlockAttrs` icon attribute
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the icon attribute of a block via the /api/attr/setBlockAttrs API. The payload is later rendered in the dynamic icon feature in an unsanitized context, leading to stored XSS and, in the desktop environment, potential remote code execution (RCE). This issue bypasses the previous fix for issue #15970 (XSS → RCE via dynamic icons). Version 3.5.4 contains an updated fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23852?
CVE-2026-23852 is considered a high severity vulnerability due to its potential for stored Cross-Site Scripting (XSS) and remote code execution (RCE).
How do I fix CVE-2026-23852?
To fix CVE-2026-23852, upgrade SiYuan to version 3.5.4 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-23852?
CVE-2026-23852 is a stored Cross-Site Scripting (XSS) vulnerability that can also lead to remote code execution (RCE).
Which versions of SiYuan are affected by CVE-2026-23852?
SiYuan versions prior to 3.5.4 are affected by CVE-2026-23852.
Can CVE-2026-23852 be exploited remotely?
Yes, CVE-2026-23852 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.