Skip to content
Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages

Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages

First seen 22 Jun 2026, 09:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 23, 2026 at 09:10 UTC
  • CVE-2026-56395 and CVE-2026-56397 expose SiYuan users to remote code execution risks.
  • Attackers can exploit the flaw through malicious package metadata in the Bazaar marketplace.
  • Users must upgrade to SiYuan version 3.6.1 or later to mitigate the vulnerability.

SiYuan disclosed CVE-2026-56395, a critical remote code execution vulnerability affecting versions before 3.6.1. The flaw arises from improper sanitization of Bazaar marketplace package metadata, allowing malicious authors to inject HTML and JavaScript. This can lead to cross-site scripting and, due to Electron's nodeIntegration, execution of OS commands on victim devices. The vulnerability has a CVSS score of 9.6 (v3.1) and 9.4 (v4.0). Users are advised to upgrade to SiYuan version 3.6.1 or later and avoid untrusted packages. CVE-2026-56397 was also published with similar details, indicating a broader issue within the Bazaar marketplace.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-21
CVE-2026-56395 published
SiYuan disclosed a critical RCE vulnerability due to improper sanitization in the Bazaar marketplace.
Mallory.Ai
2026-06-21
CVE-2026-56397 published
Another critical RCE vulnerability was disclosed, highlighting ongoing issues in the Bazaar marketplace.
cvefeed.io
Recent
Users urged to upgrade
SiYuan recommends users upgrade to version 3.6.1 or later to avoid exploitation risks.
Mallory.Ai

More articles in this cluster (7)

Following this threat?

Track SiYuan and CVE-2026-56395 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed