Skip to content

CVE-2026-54158

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 25, 2026
Last Seen
June 25, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

SiYuan, an open-source personal knowledge management system, has disclosed a critical stored cross-site scripting (XSS) vulnerability that can escalate to remote code execution (RCE) in its Electron desktop client. The flaw, tracked as CVE-2026-54158, affects versions prior to 3.7.0 and arises from...

Public Exploits

Checking GitHub for proof-of-concept code…