---
id: CVE-2026-66396
title: >-
  SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List
  value when rendering Gallery and Kanban cover images, allowing stored
  cross-site scripting via unescaped style attribute interpolation
summary: >-
  SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List
  value when rendering Gallery and Kanban cover images, allowing stored
  cross-site scripting via unescaped style attribute interpolation. Attackers
  with editor pe…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.7.2
published: '2026-07-27'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:03.607'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66396'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5rxg-wh59-mg34
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-stored-xss-to-rce-via-title-img-ial
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5rxg-wh59-mg34
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-27T17:27:38.513794Z'
epss: 0.00374
epssPercentile: 0.3113
ingestedAt: '2026-09-17T18:25:15.982Z'
---

## Overview

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
