SiYuan is an open-source personal knowledge management system vulnerable to stored cross-site scripting (XSS) that escalates to arbitrary code execution in desktop environments. Versions 3.6.3 and below are affected due to unsafe rendering of Mermaid diagrams with loose security settings and DOM injection via innerHTML, allowing malicious javascript: URLs to persist in the rendered output. The vulnerability has been patched in version 3.6.4. The vulnerability carries a critical CVSS score of 9.0 with a network-based attack vector, low complexity, and low privilege requirements, though user interaction is necessary. The attack requires a victim to open a note containing malicious Mermaid code and click on the rendered diagram. On Electron-based desktop builds with nodeIntegration enabled and contextIsolation disabled, successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability. The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS probability score of 0.00048 suggests minimal real-world exploitation activity. Community awareness appears limited, with the issue representing a moderate risk (52/100 on FAUCET scale) primarily to users who have not upgraded to version 3.6.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.4CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.