Skip to content
CVE Alert: CVE-2026-86712 – siyuan-note

CVE Alert: CVE-2026-86712 – siyuan-note

Redpacketsecurity admin September 8, 2026

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.

High-risk local compromise requiring prompt remediation; KEV status, SSVC exploitation state and EPSS score are not provided, so active exploitation cannot be confirmed.

A successful attack can give an adversary the same effective control as the user, enabling theft or alteration of confidential notes, credential material and locally accessible files. It could also support malware installation, surveillance or disruption, particularly where the application is used for operational knowledge or sensitive research.

Most likely attack path

The attack is network-deliverable (AV:N), requires low effort and no existing privileges (AC:L, PR:N), but depends on active user interaction (UI:A), such as pasting attacker-prepared content. Scope is unchanged, so direct impact is concentrated on the host; however, stolen tokens, files or credentials could enable subsequent movement into connected services.

Users running the desktop application on workstations that browse untrusted sites, process externally supplied content or hold sensitive notes are the primary targets. Risk is higher on developer, administrator and research endpoints with broad filesystem or cloud-session access.

Alert on the application spawning shells, scripting engines or unexpected child processes.

Review clipboard-related activity preceding suspicious application launches.

Hunt for new binaries, persistence entries and outbound connections from the application.

Investigate unusual access to browser profiles, SSH material, tokens or sensitive documents.

Mitigation and prioritisation

Upgrade promptly to the vendor-fixed release; treat as an emergency endpoint patch where exposure is widespread.

Until patched, restrict untrusted browsing and avoid pasting external content into the application.

Apply application allow-listing and endpoint controls to block unexpected child-process execution.

If KEV is confirmed or EPSS is at least 0.5, **treat as priority 1**; verify exploitation status before deferring through change control.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (1)