logo

Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution

ID: 10654841-6149-57dd-b980-c0296b7d840f

STIX ID: report--10654841-6149-57dd-b980-c0296b7d840f

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

SiYuan disclosed a critical stored cross-site scripting (XSS) vulnerability (CVE-2026-54158) in its Electron desktop client that can escalate to remote code execution due to unsafe HTML rendering in attribute-view cells and insecure Electron settings; the flaw affects versions prior to 3.7.0 (CVSS 9.9) and users are urged to upgrade to 3.7.0 to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.