Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution

Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution

First seen 25 Jun 2026, 09:23 UTC Mallory.AiFeedlycvefeed.iocve.akaoma.comnvd.nist.gov+3 86% similarity 78.0
Share:

Article Content

Browse articles
ThreatCluster

SiYuan, an open-source personal knowledge management system, has disclosed a critical stored cross-site scripting (XSS) vulnerability that can escalate to remote code execution (RCE) in its Electron desktop client. The flaw, tracked as CVE-2026-54158, affects versions prior to 3.7.0 and arises from unsafe HTML rendering in attribute-view cells. Attackers can exploit this vulnerability by inserting malicious content into text, URL, phone, and asset fields, which is then executed when a victim interacts with the affected content. The impact is exacerbated by insecure Electron settings, allowing injected JavaScript to access Node.js APIs. This vulnerability was published on June 24, 2026, and has a CVSS score of 9.9, indicating its critical nature. Users are advised to upgrade to version 3.7.0 to mitigate the risk. Two related advisories were published on June 3, 2026, highlighting similar stored XSS vulnerabilities in SiYuan's attribute-view rendering.

Key Points: • CVE-2026-54158 allows stored XSS to escalate to RCE in SiYuan's Electron client. • The vulnerability affects all versions prior to 3.7.0 and has a CVSS score of 9.9. • Users are urged to upgrade to SiYuan version 3.7.0 to mitigate the risk.

ThreatCluster AI

Timeline

2026-06-03
Security advisories published
Two GitHub advisories disclosed stored XSS vulnerabilities in SiYuan's attribute-view rendering, highlighting the risk of RCE.
Mallory.Ai
2026-06-24
CVE-2026-54158 published
SiYuan disclosed a critical stored XSS vulnerability that escalates to RCE in the Electron desktop client, affecting versions prior to 3.7.0.
Mallory.Ai
2026-06-24
CVE-2026-50551 published
The National Vulnerability Database published details on another critical stored XSS vulnerability in SiYuan, also affecting versions before 3.7.0.
nvd.nist.gov

Community

Browse all →