cvefeed.io Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages
Article Content
- •CVE-2026-56395 and CVE-2026-56397 expose SiYuan users to remote code execution risks.
- •Attackers can exploit the flaw through malicious package metadata in the Bazaar marketplace.
- •Users must upgrade to SiYuan version 3.6.1 or later to mitigate the vulnerability.
SiYuan disclosed CVE-2026-56395, a critical remote code execution vulnerability affecting versions before 3.6.1. The flaw arises from improper sanitization of Bazaar marketplace package metadata, allowing malicious authors to inject HTML and JavaScript. This can lead to cross-site scripting and, due to Electron's nodeIntegration, execution of OS commands on victim devices. The vulnerability has a CVSS score of 9.6 (v3.1) and 9.4 (v4.0). Users are advised to upgrade to SiYuan version 3.6.1 or later and avoid untrusted packages. CVE-2026-56397 was also published with similar details, indicating a broader issue within the Bazaar marketplace.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track SiYuan and CVE-2026-56395 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…