GHSA-24r3-p3x6-cqvxCritical· 9.6▾ MidnightDuplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-v3mg-9v85-fcm7. This link is maintained to preserve external references.
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.
github.com/siyuan-note/siyuan/kernel <= 0.0.0-20260313024916-fd6526133bb3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-56395MediumRejected reason: This record is a duplicate; use CVE-2026-56397 instead.
GHSA-99rq-75j6-5j9fHigh· 8.7SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
CVE-2026-50551Critical· 9.9SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-54067Critical· 9.9SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-54070High· 7.1SiYuan: Stored XSS in Bazaar marketplace via package README event handlers