CVE-2026-39846
SiYuan, a personal knowledge management system, had a critical flaw before version 3.6.4 that let a malicious note trigger remote code execution when synced to another user. The flaw was caused by unsanitized table caption content that was rendered as HTML, allowing attacker‑controlled JavaScript to run with full Node.js access. The issue is fixed in version 3.6.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SiYuan users running any version earlier than 3.6.4 who sync notes between devices.
Real-world impact
An attacker could inject a crafted note, have the victim sync it, and then run arbitrary code on the victim’s computer with full Node.js privileges, potentially taking control of the system, stealing data, or installing malware.
Why this severity
The CVSS score of 9.0 reflects a network‑based attack that requires low effort, low privileges, and only user interaction to trigger. Once exploited, the attacker gains full confidentiality, integrity, and availability compromise.
What to do about it
- 01Upgrade SiYuan to version 3.6.4 or later.
NVD-referenced vendor advisory
Timeline
- Apr 7, 2026 · Apr 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/siyuan-note/siyuan/security…exploitvendor advisory