logo

Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages

ID: e619aa51-820d-58ef-aa00-0ae13e764159

STIX ID: report--e619aa51-820d-58ef-aa00-0ae13e764159

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

...
...

SiYuan disclosed two critical vulnerabilities (CVE-2026-56395 and CVE-2026-56397) affecting versions before 3.6.1 that allow malicious Bazaar marketplace package metadata to inject HTML/JavaScript, enabling cross-site scripting and remote code execution via Electron's nodeIntegration; CVSS scores are 9.6 (v3.1) and 9.4 (v4.0), and users are advised to upgrade to SiYuan 3.6.1 or later and avoid untrusted packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.