CVE-2026-86712

high

Description

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.

References

https://www.vulncheck.com/advisories/siyuan-before-3.8.2-remote-code-execution-via-clipboard

https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9rr9-pxr4-gcgc

https://github.com/siyuan-note/siyuan/releases/tag/v3.8.2

https://github.com/siyuan-note/siyuan/commit/9ce660652de2ced26ec2d98a5a242cb0b8bb7273

https://github.com/siyuan-note/siyuan/blob/v3.8.1/app/src/protyle/util/paste.ts

https://github.com/siyuan-note/siyuan

Details

Source: Mitre, NVD

Published: 2026-09-08

Updated: 2026-09-08

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 8.6

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High