---
id: CVE-2026-87811
title: >-
  SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input
  value attributes without proper attribute encoding
summary: >-
  SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input
  value attributes without proper attribute encoding. Attackers can craft
  malicious template paths that break out of the attribute context and execute
  JavaScrip…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.2
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:20:21.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87811'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-v6wf-r2gr-rrgf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-notebook-template-paths
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T12:18:24.227560Z'
ingestedAt: '2026-09-14T10:09:14.762Z'
epss: 0.00367
epssPercentile: 0.27826
---

## Overview

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScript when a victim opens notebook configuration, enabling same-origin API requests and application state manipulation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
