Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
NVD published the first details for CVE-2026-50551
Feedly found the first article mentioning CVE-2026-50551 . See article
CVE-2026-50551 | SiYuan up to 3.6.x cross site scripting (GHSA-56mp-4f3v-fgj2)
CVE-2026-50551 - SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content CVE ID : CVE-2026-50551 Published : June 24, 2026, 9:20 p.m. | 3 hours, 50 minutes ago Description : SiYuan is an open-source personal knowledge management system. Prior to 3.7.0...
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
