---
id: CVE-2026-87813
title: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  the Search Assets result list where asset filenames are interpolated into HTML
  without escaping
summary: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  the Search Assets result list where asset filenames are interpolated into HTML
  without escaping. Authenticated attackers can craft asset filenames containing
  ma…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.2
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:20:21.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87813'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-qcw6-qm34-28h8
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-unescaped-asset-filenames
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-qcw6-qm34-28h8
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T14:06:05.261922Z'
ingestedAt: '2026-09-14T09:50:30.797Z'
epss: 0.00367
epssPercentile: 0.27826
---

## Overview

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing malicious markup that executes JavaScript in the victim's browser when searching assets, enabling same-origin API requests and application state manipulation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
