Record summary

CVE-2026-50551 has a selected CVSS score of 9.9 (critical).

Description

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 3.7.0affected

github.com/siyuan-note/siyuan/kernel

Browse Go / github.com/siyuan-note/siyuan/kernel
GitHub AdvisoryBefore 0.0.0-20260628153353-2d5d72223df4 · Fixed in 0.0.0-20260628153353-2d5d72223df4affected

References

3