CVE-2026-93923: SiYuan through 3.8.4 Stored XSS via Heading Style Attribute

Published Sep 18, 2026
·
Updated

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

Affected Software

1 affected component
SiYuan<=3.8.4

Event History

Sep 18, 2026
CVE Published
via MITRE·11:12 PM
Data Sourced
via MITRE·11:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Users who open a crafted notebook are exposed because malicious heading style values can be stored and later rendered in the outline or bookmark dock. Administrative endpoints can also be used to inject the malicious values.

2

What does an attacker need to exploit this issue?

An attacker needs to get crafted heading style values into a notebook or access administrative endpoints that accept those values. Victim interaction is required for the malicious content to execute in the Electron renderer.

3

What is the impact if exploitation succeeds?

The stored script executes in the Electron renderer with full system access. This can affect confidentiality, integrity, and availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203