Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution. | |
| Title | SiYuan through 3.8.4 Stored XSS via notebook names | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T23:12:08.503Z
Reserved: 2026-09-18T21:57:00.085Z
Link: CVE-2026-93922
No data.
Status : Deferred
Published: 2026-09-19T00:16:57.783
Modified: 2026-09-19T00:16:57.913
Link: CVE-2026-93922
No data.
OpenCVE Enrichment
No data.
