Threat intelligence dashboard
CVE-2026-100643high

SiYuan before v3.8.4 Stored XSS via Attribute View textarea

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.

Risk score

8.5

CVSS 4.0

Vendor
siyuan-note
Product
siyuan
CWE
CWE-79
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

siyuan

siyuan-note

Version / rangeStatusType
2.10.8 to before 3.8.4affectedsemver
3.8.4unaffectedsemver

Technical metrics

8.5

CVSS 4.0

Severity
high
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

8.0

CVSS 3.1

Severity
high
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H