---
id: CVE-2026-87814
title: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  the search asset preview feature that fails to escape indexed asset content
  before inserting it into the DOM using innerHTML
summary: >-
  SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in
  the search asset preview feature that fails to escape indexed asset content
  before inserting it into the DOM using innerHTML. Attackers who can place
  crafted te…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.2
published: '2026-09-09'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:34.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87814'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-64gp-333q-mq6j
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-asset-preview
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00367
epssPercentile: 0.27826
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T17:08:28.375371Z'
ingestedAt: '2026-09-09T12:08:31.841Z'
---

## Overview

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
