Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40322

30
FAUCET Score

SiYuan is an open-source personal knowledge management system vulnerable to stored cross-site scripting (XSS) that escalates to arbitrary code execution in desktop environments. Versions 3.6.3 and below are affected due to unsafe rendering of Mermaid diagrams with loose security settings and DOM injection via innerHTML, allowing malicious javascript: URLs to persist in the rendered output. The vulnerability has been patched in version 3.6.4. The vulnerability carries a critical CVSS score of 9.0 with a network-based attack vector, low complexity, and low privilege requirements, though user interaction is necessary. The attack requires a victim to open a note containing malicious Mermaid code and click on the rendered diagram. On Electron-based desktop builds with nodeIntegration enabled and contextIsolation disabled, successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability. The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS probability score of 0.00048 suggests minimal real-world exploitation activity. Community awareness appears limited, with the issue representing a moderate risk (52/100 on FAUCET scale) primarily to users who have not upgraded to version 3.6.4.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.4CPE matchmatch criteria
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
22.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 15th percentile among its peer group of 265 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / siyuan-note/siyuan/releases/tag/v3.6.4
Release Notes
github.com / siyuan-note/siyuan/security/advisories/GHSA-x63q-3rcj-hhp5
Third Party Advisory