SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66396

HIGH · CVSS 8.4 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

SiYuan versions prior to 3.7.2 are vulnerable to stored cross-site scripting due to improper escaping of the title-img Individual Attribute List value, which can lead to the execution of arbitrary code in the Electron renderer. This vulnerability allows attackers with editor permissions to inject malicious onload handlers, compromising the security of users who open affected documents. Organizations using SiYuan should prioritize patching this vulnerability to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66396
Severity
HIGH
CVSS
8.4
EPSS
0.30%

Original NVD Description

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.