CVE-2026-82653: SiYuan before v3.8.1 Stored XSS via confirmDialog

Published Aug 30, 2026
·
Updated

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.

Affected Software

1 affected component
SiYuan SiYuan<3.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in v3.8.1
  2. Compensating control

    Mitigate exploitation by avoiding or restricting the actions that trigger confirmation dialogs (e.g., uninstalling packages or unlocking encrypted notebooks) for affected users until SiYuan is upgraded to v3.8.1.

Event History

Aug 30, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Nov 23, 58632
Event
via NVD·11:44 PM

Frequently Asked Questions

1

Who is exposed to exploitation?

Users of SiYuan versions before v3.8.1 are exposed when they uninstall a malicious bazaar package or unlock an encrypted notebook whose name contains a malicious HTML or script payload.

2

What does an attacker need to do to exploit this issue?

An attacker needs to cause a malicious payload to be stored in a bazaar package name or notebook name. The payload executes when a user opens the affected confirmation dialog, such as during package uninstallation or encrypted-notebook unlocking.

3

Is user interaction required?

Yes. The affected user must trigger the relevant confirmation dialog by uninstalling the package or unlocking the encrypted notebook.

4

What version resolves the issue?

The issue affects SiYuan before v3.8.1. Updating to v3.8.1 or later removes the stated affected-version condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203