CVE-2026-86712: SiYuan before 3.8.2 Remote Code Execution via Clipboard

Published Sep 8, 2026
·
Updated

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.

Affected Software

1 affected component
SiYuan SiYuan<3.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.8.2
  2. Compensating control

    Block or disable clipboard write/paste from untrusted web pages/applications when using the SiYuan desktop client to reduce exposure to attacker-writable clipboard content and paste-handler code execution.

Event History

Sep 8, 2026
CVE Published
via MITRE·11:23 AM
Data Sourced
via MITRE·11:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users of SiYuan versions before 3.8.2 are exposed when they paste attacker-controlled clipboard content into the application. The attack can be delivered through a malicious web page that writes the crafted text/siyuan clipboard MIME content.

2

Does exploitation require prior access or elevated privileges?

No prior privileges are required. Exploitation requires user interaction: the target must paste the malicious clipboard data into SiYuan.

3

What is the impact after successful exploitation?

Injected scripts execute in SiYuan's Node-enabled desktop renderer with full Node.js access through the Electron main process. This can affect confidentiality, integrity, and availability.

4

What version addresses the issue?

SiYuan 3.8.2 addresses the vulnerability. Systems running a version before 3.8.2 should be updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203