Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution
ID: 10654841-6149-57dd-b980-c0296b7d840f
STIX ID: report--10654841-6149-57dd-b980-c0296b7d840f
Feed Name: ThreatCluster
Threat Score
SiYuan disclosed a critical stored cross-site scripting (XSS) vulnerability (CVE-2026-54158) in its Electron desktop client that can escalate to remote code execution due to unsafe HTML rendering in attribute-view cells and insecure Electron settings; the flaw affects versions prior to 3.7.0 (CVSS 9.9) and users are urged to upgrade to 3.7.0 to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
