github.com
https://github.com/siyuan-note/siyuan CVE-2026-50551
CRITICAL
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
Record summary
CVE-2026-50551 has a selected CVSS score of 9.9 (critical).
Description
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 3.7.0 | affected | |
github.com/siyuan-note/siyuan/kernelBrowse Go / github.com/siyuan-note/siyuan/kernel | GitHub Advisory | Before 0.0.0-20260628153353-2d5d72223df4 · Fixed in 0.0.0-20260628153353-2d5d72223df4 | affected |
References
3github.comConfirmation
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-56mp-4f3v-fgj2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-50551