Skip to content
Siyuan 3.8.4 XSS Vulnerabilities Exploited via Notebook Names and Heading Styles

Siyuan 3.8.4 XSS Vulnerabilities Exploited via Notebook Names and Heading Styles

First seen 19 Sep 2026, 20:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 00:24 UTC
  • Two XSS vulnerabilities found in Siyuan 3.8.4 via notebook names and heading attributes.
  • Both vulnerabilities are categorized under CWE-79 for improper input neutralization.
  • No active exploitation reported, but potential risks remain for affected users.

Two distinct stored Cross-Site Scripting (XSS) vulnerabilities have been identified in Siyuan version 3.8.4. The vulnerabilities are triggered through malicious notebook names and heading style attributes. Both vulnerabilities fall under CWE-79, indicating improper neutralization of input during web page generation. Affected users may face risks of data theft, session hijacking, and other malicious actions. The vulnerabilities have been documented in GitHub Security Advisories GHSA-8c2m-33v9-vvqm and GHSA-928g-4hfq-qwvx. Currently, there is no indication of active exploitation in the wild, but the potential for abuse exists. Security professionals are advised to monitor their systems for these vulnerabilities. Patching is recommended to mitigate risks associated with these flaws.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-19
Siyuan vulnerabilities disclosed
Two stored XSS vulnerabilities were published affecting Siyuan version 3.8.4, identified through notebook names and heading style attributes.
VulnCheck
2026-09-19
GitHub Security Advisories published
Advisories GHSA-8c2m-33v9-vvqm and GHSA-928g-4hfq-qwvx were released detailing the vulnerabilities.
VulnCheck

More articles in this cluster (2)