CVE-2026-66395

CRITICAL

SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol

Title source: cna
STIX 2.1

Description

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-6gx2-8gcr-x83f)
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gx2-8gcr-x83f
Third Party Advisory third-party-advisory
VulnCheck Advisory: SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol
https://www.vulncheck.com/advisories/siyuan-desktop-before-reflected-xss-to-rce-via-siyuan-protocol

Scores

CVSS v3 9.6
EPSS 0.0033
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
siyuan-note/siyuan < 3.7.2
siyuan-note/siyuan 3.7.2
Published Jul 27, 2026
Tracked Since Jul 27, 2026