Vulnary
← back to the feed
Critical· 9.3

CVE-2026-66396

SiYuan versions prior to 3.7.2 do not properly escape a style attribute used for gallery and Kanban cover images, allowing stored cross‑site scripting. An attacker with editor permissions can embed JavaScript that runs with full Node.js access when a victim opens the affected document.

publishedJul 27, 2026
last modifiedJul 28, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
22th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 10, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of the SiYuan note‑taking application using versions earlier than 3.7.2, especially those working with Gallery or Kanban views.

02

Real-world impact

An attacker can execute arbitrary code on a victim’s computer with full Node.js privileges whenever the victim opens a malicious document, potentially stealing data, installing malware, or taking complete control of the system.

03

Why this severity

The CVSS score of 9.3 reflects the high privileges required (high), the need for user interaction (partial), and the severe impact on confidentiality, integrity, and availability. The vector shows high impact on all core security objectives, making it a critical vulnerability.

04

What to do about it

no official fix yet
interim mitigations
  • Avoid opening documents from untrusted sources.
  • Restrict editor permissions to trusted users only.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredHigh
User interactionPassive
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-66396: SiYuan versions prior to 3.7.2 do not properly escape a style attribut · Vulnary