---
id: CVE-2026-92985
title: >-
  SiYuan versions before 3.8.4 fail to escape bookmark labels imported from
  notebook files when rendering them in the dock tree
summary: >-
  SiYuan versions before 3.8.4 fail to escape bookmark labels imported from
  notebook files when rendering them in the dock tree. Attackers can craft
  malicious .sy notebook files with unescaped HTML in bookmark attributes that
  execute scrip…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: siyuan-note
product: siyuan
affected:
  - siyuan < 3.8.4
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T16:18:35.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92985'
references:
  - url: 'https://github.com/siyuan-note/siyuan'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8509e7
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jhfc-9mcq-8p8v
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-via-bookmark-labels
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jhfc-9mcq-8p8v
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T15:23:05.971849Z'
ingestedAt: '2026-09-17T15:20:39.002Z'
epss: 0.00518
epssPercentile: 0.43065
---

## Overview

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
