Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages
ID: e619aa51-820d-58ef-aa00-0ae13e764159
STIX ID: report--e619aa51-820d-58ef-aa00-0ae13e764159
Feed Name: ThreatCluster
Threat Score
SiYuan disclosed two critical vulnerabilities (CVE-2026-56395 and CVE-2026-56397) affecting versions before 3.6.1 that allow malicious Bazaar marketplace package metadata to inject HTML/JavaScript, enabling cross-site scripting and remote code execution via Electron's nodeIntegration; CVSS scores are 9.6 (v3.1) and 9.4 (v4.0), and users are advised to upgrade to SiYuan 3.6.1 or later and avoid untrusted packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
