CVE-2026-82649: SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path

Published Aug 30, 2026
·
Updated

SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that includes the installer's own launch directory ahead of System32, an attacker who plants a malicious executable (e.g., a renamed TASKKILL.exe) in that directory can have it executed when the installer runs. These calls occur in electron-builder's preInit hook before the license page is displayed, and with an all-users (elevated) install the planted binary executes with an elevated token, resulting in local privilege escalation.

Affected Software

1 affected component
SiYuan (Windows installer)<3.8.1, >=2.0.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.1
  2. Compensating control

    Before upgrading to SiYuan 3.8.1, ensure the NSIS/installer launch directory (the launch directory that is ahead of System32 in the uncontrolled search path) does not contain attacker-planted executables (e.g., a renamed TASKKILL.exe).

Event History

Aug 30, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to elevated code execution?

Windows systems where an affected installer is run as an all-users installation are exposed. In that elevated installation mode, a planted executable is run with an elevated token.

2

What does an attacker need to exploit this issue?

The attacker needs to place a malicious executable with the name of a invoked system command, such as TASKKILL.exe, in the directory from which the installer is launched. The installer then resolves that local file before the legitimate System32 executable.

3

Does exploitation require the user to proceed through the installer?

No. The vulnerable calls occur in electron-builder's preInit hook, before the license page is shown, so the planted executable can run as soon as the installer starts.

4

How can I determine whether an installer is affected?

Affected SiYuan Windows installer versions are 2.0.14 through versions before 3.8.1. Version 3.8.1 and later are not identified as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203