CVE-2026-92986
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
Debilidad
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
Referencias
- https://github.com/siyuan-note/siyuan
- https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134
- https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8509e7
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-c5h9-g2c6-fxjw
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-via-document-title
Encuentra el fallo antes que un atacante.
Inicia sesión con GitHub y ejecuta tu primera auditoría en menos de un minuto. El plan gratuito no requiere tarjeta de crédito.