CVE-2026-66396
SiYuan versions prior to 3.7.2 do not properly escape a style attribute used for gallery and Kanban cover images, allowing stored cross‑site scripting. An attacker with editor permissions can embed JavaScript that runs with full Node.js access when a victim opens the affected document.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the SiYuan note‑taking application using versions earlier than 3.7.2, especially those working with Gallery or Kanban views.
Real-world impact
An attacker can execute arbitrary code on a victim’s computer with full Node.js privileges whenever the victim opens a malicious document, potentially stealing data, installing malware, or taking complete control of the system.
Why this severity
The CVSS score of 9.3 reflects the high privileges required (high), the need for user interaction (partial), and the severe impact on confidentiality, integrity, and availability. The vector shows high impact on all core security objectives, making it a critical vulnerability.
What to do about it
- ›Avoid opening documents from untrusted sources.
- ›Restrict editor permissions to trusted users only.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources