---
id: CVE-2026-87812
title: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  Bazaar package cards where the iconURL metadata is inserted directly into HTML
  img src attributes without escaping
summary: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  Bazaar package cards where the iconURL metadata is inserted directly into HTML
  img src attributes without escaping. Attackers can inject malicious URLs with
  eve…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.2
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:17:53.837'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87812'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rvcf-q4h8-w6c9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-bazaar-iconurl
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:18:52.230953Z'
ingestedAt: '2026-09-14T13:12:38.417Z'
epss: 0.00362
epssPercentile: 0.27288
---

## Overview

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
