Critical CVE-2026-86712 Vulnerability in SiYuan Note Exposes Users to Code Execution Risks

Critical CVE-2026-86712 Vulnerability in SiYuan Note Exposes Users to Code Execution Risks

First seen 9 Sep 2026, 15:15 UTC Redpacketsecuritywww.vulncheck.comOsv.Dev 64.5

Article Content

Browse articles
ThreatCluster

A high-risk vulnerability, CVE-2026-86712, has been identified in SiYuan Note versions prior to 3.8.2. The flaw allows attackers to exploit the application by leveraging an attacker-writable clipboard MIME type, enabling code execution through the Electron main process. Users are at risk, particularly those handling sensitive information, as successful exploitation can lead to unauthorized access to confidential notes and files. The vulnerability requires user interaction to exploit, specifically through pasting malicious content. It has been classified with a CVSS score of 8.6, indicating a high severity level. Immediate remediation is advised, including upgrading to the patched version and restricting untrusted browsing. The vulnerability was published on September 8, 2026, and no active exploitation has been confirmed yet.

Key Points: • CVE-2026-86712 allows code execution in SiYuan Note via clipboard exploitation. • Affected users include those handling sensitive data, particularly on developer and research endpoints. • Immediate upgrade to version 3.8.2 is recommended to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-86712 published
The vulnerability in SiYuan Note was officially disclosed, highlighting risks of code execution via clipboard misuse.
Redpacketsecurity
2026-09-09
CVE-2026-86712 reported by OSV
OSV confirms the vulnerability's details and severity, reiterating the need for urgent patching.
Osv.Dev