Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39846

34
FAUCET Score

SiYuan prior to version 3.6.4 contains a stored cross-site scripting (XSS) vulnerability in table caption content that fails to properly escape user input before rendering into HTML. When a malicious note is synced across users in a shared workspace, the vulnerability can be exploited to achieve remote code execution in the Electron desktop client, which runs with both nodeIntegration enabled and contextIsolation disabled, allowing attacker-controlled JavaScript to access dangerous Node.js APIs. The vulnerability carries a CVSS score of 9.0 (Critical) with a network-based attack vector, low complexity, and the requirement for low privileges and user interaction. The impact is severe across confidentiality, integrity, and availability, as successful exploitation grants the attacker full code execution capabilities on the victim's system. An attacker need only craft a malicious note and wait for the victim to sync and open it. There is no evidence of active exploitation in the wild at this time, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and marked as inactive on public hot lists. The EPSS score of 0.00155 indicates low probability of exploitation attempts relative to the broader CVE landscape, though the critical nature of the vulnerability warrants immediate patching to version 3.6.4 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.4CPE matchmatch criteria
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 41st percentile among its peer group of 265 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/siyuan-note/siyuan/kernelFixed in: 0.0.0-20260407035653-2f416e5253f1

Vendor Advisories (1)

goGHSA-phhp-9rm9-6gr2critical

SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions

Apr 8, 2026

References

github.com / siyuan-note/siyuan/security/advisories/GHSA-phhp-9rm9-6gr2
ExploitVendor Advisory