VYPR
High severity8.8NVD Advisory· Published Sep 19, 2026· Updated Sep 19, 2026

CVE-2026-93923

CVE-2026-93923

Description

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.